CVE-2003-1413: Path Traversal
parsexml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1413?
CVE-2003-1413 is considered to be of moderate severity due to its ability to allow unauthorized file access via error message analysis.
How do I fix CVE-2003-1413?
The fix for CVE-2003-1413 involves upgrading to versions that are not vulnerable, specifically version 4.1.2 or later of Apple Darwin Streaming Server.
Which software is affected by CVE-2003-1413?
CVE-2003-1413 affects Apple Darwin Streaming Server version 4.1.1 and Apple Quicktime Streaming Server version 4.1.1.
What type of attack does CVE-2003-1413 facilitate?
CVE-2003-1413 facilitates directory traversal attacks that allow attackers to determine the existence of arbitrary files on the server.
Can CVE-2003-1413 be exploited remotely?
Yes, CVE-2003-1413 can be exploited remotely by attackers sending crafted requests to the affected servers.