CVE-2004-1548

Properties

Published:
30.12.2004
Updated:
16.08.2006
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    ONNURI INFOTEK: ActivePost Standard

    Vulnerability description

    Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.

    References:

    BID: http://www.securityfocus.com/bid/11244
    SECUNIA: http://secunia.com/advisories/12642/
    XF: http://xforce.iss.net/xforce/xfdb/17488
    Luigi Auriemma: http://aluigi.altervista.org/adv/actp-adv.txt
    SECTRACK: http://securitytracker.com/id?1011406
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109597139011373&w=2