CVE-2005-3136

Properties

Published:
03.10.2005
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    Virtools: Web Player

    Vulnerability description

    Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=112811771331997&w=2
    http://aluigi.altervista.org/adv/virtbugs-adv.txt: http://aluigi.altervista.org/adv/virtbugs-adv.txt
    BID: http://www.securityfocus.com/bid/14991
    SECUNIA: http://secunia.com/advisories/17034/
    XF: http://xforce.iss.net/xforce/xfdb/22471
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=112811771331997&w=2
    SECTRACK: http://securitytracker.com/id?1014993