First published: Tue Dec 20 2005(Updated: )
Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | =2.0 | |
Ht Editor | =2.1 | |
Ht Editor | =2.1a | |
Ht Editor | =2.2a | |
Ht Editor | =2.3 | |
Ht Editor | =2.3.1 | |
Ht Editor | =2.3.2 | |
Ht Editor | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4421 has a medium severity rating as it exposes sensitive directories to remote attackers.
To fix CVE-2005-4421, upgrade to Dev-Editor version 3.1 or later, which addresses this directory traversal vulnerability.
The potential impacts of CVE-2005-4421 include unauthorized access to sensitive files and information stored outside the web root.
CVE-2005-4421 affects versions 2.0 to 3.0 of Dev-Editor, allowing remote directory access.
Yes, there is a patch included in Dev-Editor version 3.1 and newer to mitigate the vulnerability.