Lucene search

K
cveMitreCVE-2002-0144
HistoryMar 25, 2002 - 5:00 a.m.

CVE-2002-0144

2002-03-2505:00:00
mitre
web.nvd.nist.gov
24
cve-2002-0144
chuid 1.2
directory traversal
remote attack
ownership change
dot attack.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.007

Percentile

80.6%

Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a … (dot dot) attack.

Affected configurations

Nvd
Node
scott_parishchuidMatch1.0
OR
scott_parishchuidMatch1.1
OR
scott_parishchuidMatch1.2
VendorProductVersionCPE
scott_parishchuid1.0cpe:2.3:a:scott_parish:chuid:1.0:*:*:*:*:*:*:*
scott_parishchuid1.1cpe:2.3:a:scott_parish:chuid:1.1:*:*:*:*:*:*:*
scott_parishchuid1.2cpe:2.3:a:scott_parish:chuid:1.2:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.007

Percentile

80.6%

Related for CVE-2002-0144