CVE-2004-2253: Medium severity Netwin Surgeldap vulnerability
Published Dec 31, 2004
·Updated
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.
Affected Software
3 affected components
Netwin Surgeldap=1.0e
Netwin Surgeldap=1.0g
Netwin Surgeldap=1.0d
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2253?
CVE-2004-2253 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2004-2253?
To fix CVE-2004-2253, upgrade SurgeLDAP to version 1.0h or later, which addresses this directory traversal vulnerability.
3
What systems are affected by CVE-2004-2253?
CVE-2004-2253 affects SurgeLDAP versions 1.0d, 1.0e, and 1.0g.
4
What type of attack is possible with CVE-2004-2253?
CVE-2004-2253 allows remote attackers to exploit a directory traversal vulnerability to read arbitrary files on the server.
5
Is CVE-2004-2253 easily exploitable?
Yes, CVE-2004-2253 can be easily exploited by sending crafted requests to the vulnerable user.cgi script.