GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2002-06-25T04:00:00

Updated: 2024-08-08T02:42:28.488Z

Reserved: 2002-05-01T00:00:00

Link: CVE-2002-0196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2002-05-16T04:00:00.000

Modified: 2008-09-11T00:00:41.383

Link: CVE-2002-0196

cve-icon Redhat

No data.