CVE-2000-1048: Medium severity Qbik WinGate vulnerability
Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1048?
CVE-2000-1048 has been classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2000-1048?
To fix CVE-2000-1048, update the Wingate software to the latest version that addresses this directory traversal vulnerability.
Which versions of Wingate are affected by CVE-2000-1048?
CVE-2000-1048 affects Wingate versions 2.1, 3.0, 4.0.1, and the 4.1 Beta A release.
What type of attack does CVE-2000-1048 exploit?
CVE-2000-1048 exploits a directory traversal attack through HTTP GET requests using encoded characters.
Can CVE-2000-1048 allow attackers to access files outside the web root?
Yes, CVE-2000-1048 enables attackers to read arbitrary files outside the web root directory through a directory traversal attack.