First published: Thu Aug 14 2003(Updated: )
Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Iplanet Directory Server | =5.0 | |
Sun ONE Directory Server | =5.1-sp1 | |
Sun ONE Directory Server | =5.1 | |
Sun Iplanet Directory Server | =5.1-sp2 | |
Sun Iplanet Directory Server | =5.1 | |
Sun ONE Directory Server | =5.0_sp2 | |
Sun ONE Directory Server | =5.0-sp1 | |
Sun ONE Directory Server | =5.0 | |
Sun Iplanet Directory Server | =5.1-sp1 | |
Sun ONE Directory Server | =5.1-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0676 is classified as a medium severity vulnerability, allowing unauthorized file access.
To fix CVE-2003-0676, upgrade to a secure version of the iPlanet Administration Server that patches this directory traversal vulnerability.
CVE-2003-0676 affects iPlanet and Sun ONE Directory Servers, specifically versions 5.0 and 5.1.
The potential impact of CVE-2003-0676 includes the ability for remote attackers to read arbitrary files on the server.
Yes, CVE-2003-0676 is a publicly documented vulnerability that has been discussed in security forums.