CVE-2003-1413
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2003-12-31 CVE Published
- 2007-10-19 CVE Reserved
- 2024-08-08 CVE Updated
- 2024-08-08 First Exploit
- 2024-08-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/3260 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/313517 | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11445 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/6992 | 2024-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Darwin Streaming Server Search vendor "Apple" for product "Darwin Streaming Server" | 4.1.2 Search vendor "Apple" for product "Darwin Streaming Server" and version "4.1.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Streaming Server Search vendor "Apple" for product "Quicktime Streaming Server" | 4.1.1 Search vendor "Apple" for product "Quicktime Streaming Server" and version "4.1.1" | - |
Affected
|