CVE-2003-1413
4.3
CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Description
parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
None
Availability
P
Affected Software Configurations
- a apple darwin_streaming_server 4.1.2 * * * * * * *
- a apple quicktime_streaming_server 4.1.1 * * * * * * *
Weaknesses (CWE)
- CWE-22
References & External Links
- http://securityreason.com/securityalert/3260
- http://www.securityfocus.com/archive/1/313517
- http://www.securityfocus.com/bid/6992
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11445
- http://securityreason.com/securityalert/3260
- http://www.securityfocus.com/archive/1/313517
- http://www.securityfocus.com/bid/6992
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11445