CVE

Id
2472  
CVE No.
CVE-2000-0903  
Status
Candidate  
Description
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.  
Phase
Proposed (20001129)  
Votes
ACCEPT(2) Baker, Mell | NOOP(3) Cole, Collins, Wall  
Comments
Collins> Assigning CVE numbers for demo software is not appropriate | Baker> Was this a beta version in the demo disk? I don"t think it was. While we do have an exclusion for beta software, | software that is distributed as production software, just limited in scope, does not mean beta.. | The current version is 4, but it is still offered for free download from their website for use. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | Baker> SHould change vote from review to accept