Executive Summary

Informations
Name CVE-2002-1483 First vendor Publication 2003-04-22
Vendor Cve Last vendor Modification 2008-09-05

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1483

CWE : Common Weakness Enumeration

% Id Name

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

OpenVAS Exploits

Date Description
2005-11-03 Name : DB4Web directory traversal
File : nvt/db4web_dir_trav.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
14484 DB4Web Server db4web_c Filename Request Traversal Arbitrary File Access

Snort® IPS/IDS

Date Description
2014-01-10 db4web_c directory traversal attempt
RuleID : 3674 - Revision : 13 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

Date Description
2002-12-02 Name : A web application running on the remote host has an directory traversal vulne...
File : db4web_dir_trav.nasl - Type : ACT_ATTACK

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/5723
BUGTRAQ http://archives.neohapsis.com/archives/bugtraq/2002-09/0197.html
CONFIRM http://www.db4web.de/download/homepage/hotfix/readme_en.txt
VULNWATCH http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0124.html
XF http://www.iss.net/security_center/static/10123.php

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
Date Informations
2021-05-04 12:01:49
  • Multiple Updates
2021-04-22 01:01:56
  • Multiple Updates
2020-05-23 00:15:09
  • Multiple Updates
2014-02-17 10:25:26
  • Multiple Updates
2014-01-19 21:21:49
  • Multiple Updates
2013-05-11 12:13:27
  • Multiple Updates