CVE-2004-2184
published 2004-12-31CVE-2004-2184: Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..\"…
PriorityP339medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EXPLOIT
EPSS
8.10%
94.1th percentile
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..\" sequences in commands such as (1) dir or (2) put.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| digicraft_software | yak | — | — |
| digicraft_software | yak | — | — |
| digicraft_software | yak | — | — |
| digicraft_software | yak | — | — |
| digicraft_software | yak | — | — |
| digicraft_software | yak | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://aluigi.altervista.org/adv/yak-adv.txthttp://marc.info/?l=full-disclosure&m=109788315103778&w=2http://secunia.com/advisories/12849http://securitytracker.com/id?1011708http://www.osvdb.org/10763http://www.securityfocus.com/archive/1/378533http://www.securityfocus.com/bid/11433https://exchange.xforce.ibmcloud.com/vulnerabilities/17740http://aluigi.altervista.org/adv/yak-adv.txthttp://marc.info/?l=full-disclosure&m=109788315103778&w=2http://secunia.com/advisories/12849http://securitytracker.com/id?1011708http://www.osvdb.org/10763http://www.securityfocus.com/archive/1/378533http://www.securityfocus.com/bid/11433https://exchange.xforce.ibmcloud.com/vulnerabilities/17740
2004-12-31
Published