Lucene search

K
cve[email protected]CVE-2003-0977
HistoryJan 05, 2004 - 5:00 a.m.

CVE-2003-0977

2004-01-0505:00:00
web.nvd.nist.gov
26
cvs server
vulnerability
directory creation
file creation
root directory
malformed requests
cve-2003-0977

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.3%

CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.

Affected configurations

NVD
Node
cvscvsMatch1.10.7
OR
cvscvsMatch1.10.8
OR
cvscvsMatch1.11
OR
cvscvsMatch1.11.1
OR
cvscvsMatch1.11.1_p1
OR
cvscvsMatch1.11.2
OR
cvscvsMatch1.11.3
OR
cvscvsMatch1.11.4
OR
cvscvsMatch1.11.5
OR
cvscvsMatch1.11.6
Node
slackwareslackware_linuxMatch8.1
OR
slackwareslackware_linuxMatch9.0
OR
slackwareslackware_linuxMatch9.1

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.3%