CVE
- Id
- 5909
- CVE No.
- CVE-2002-1525
- Status
- Candidate
- Description
- Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.
- Phase
- Proposed (20030317)
- Votes
- ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | RECAST(1) Christey
- Comments
- Christey> This should probably be SPLIT (".." and absolute path are | typically different types of bugs.)