Lucene search

K
cve[email protected]CVE-2004-2184
HistoryJul 10, 2005 - 4:00 a.m.

CVE-2004-2184

2005-07-1004:00:00
web.nvd.nist.gov
18
cve-2004-2184
digicraft yak! server
directory traversal
remote attackers
arbitrary files

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.4 High

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.4%

Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via “…/” or "…" sequences in commands such as (1) dir or (2) put.

Affected configurations

NVD
Node
digicraft_softwareyakMatch2.0
OR
digicraft_softwareyakMatch2.0.1
OR
digicraft_softwareyakMatch2.0.2
OR
digicraft_softwareyakMatch2.1.0
OR
digicraft_softwareyakMatch2.1.1
OR
digicraft_softwareyakMatch2.1.2

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.4 High

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.4%

Related for CVE-2004-2184