CVE

Id
6219  
CVE No.
CVE-2002-1837  
Status
Candidate  
Description
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.  
Phase
Assigned (20050629)  
Votes
None (candidate not yet proposed)  
Comments