First published: Tue Jun 11 2002(Updated: )
Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0415 is rated as a moderate severity vulnerability due to potential exposure of sensitive files.
To fix CVE-2002-0415, update to a patched version of RealPlayer that addresses the directory traversal vulnerability.
CVE-2002-0415 affects RealPlayer 6.0.7 and potentially other versions.
CVE-2002-0415 enables directory traversal attacks which might allow local users to access unauthorized files.
CVE-2002-0415 may potentially be exploitable remotely through HTTP GET requests targeting a vulnerable RealPlayer installation.