cbcvebase.
CVE-2008-2403
published 2008-06-04

CVE-2008-2403: Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers…

critical10CVSS 3.1
AVNACLAuNCCICAC
Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method.

Affected

3 ranges
VendorProductVersion rangeFixed in
sunjava_asp_server<= 4.0.2
sunjava_asp_server
sunjava_asp_server