CVE
- Id
- 2472
- CVE No.
- CVE-2000-0903
- Status
- Candidate
- Description
- Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- Phase
- Proposed (20001129)
- Votes
- ACCEPT(2) Baker, Mell | NOOP(3) Cole, Collins, Wall
- Comments
- Collins> Assigning CVE numbers for demo software is not appropriate | Baker> Was this a beta version in the demo disk? I don"t think it was. While we do have an exclusion for beta software, | software that is distributed as production software, just limited in scope, does not mean beta.. | The current version is 4, but it is still offered for free download from their website for use. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | Baker> SHould change vote from review to accept