CVE-2003-1413

CWE-22Path Traversal3 documents3 sources
Severity
4.3MEDIUM
EPSS
0.3%
top 49.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateApr 29

Description

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-48g3-9q4j-7w5f: parse_xml2022-04-29
CVEList
CVE-2003-1413: parse_xml2007-10-20