CVE
- Id
- 11020
- CVE No.
- CVE-2004-2594
- Status
- Candidate
- Description
- Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "/" in a pathname argument, as demonstrated by "download /server.cfg".
- Phase
- Assigned (20051129)
- Votes
- None (candidate not yet proposed)
- Comments