RSS   Vulnerabilities for 'IDS'   RSS

2002-12-31
 
CVE-2002-1837

 

 
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

 

 >>> Vendor: IDS 3 Products
IDS
Nc854
Nc856


Copyright 2024, cxsecurity.com

 

Back to Top