CVE-2004-2565

N/A Unknown
Published: December 31, 2004 Modified: April 16, 2026
View on NVD

Description

Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/11748
Source: cve@mitre.org
Exploit Vendor Advisory
http://securitytracker.com/id?1010353
Source: cve@mitre.org
Exploit
http://www.osvdb.org/6585
Source: cve@mitre.org
Exploit
http://www.securityfocus.com/bid/10444
Source: cve@mitre.org
Exploit
http://secunia.com/advisories/11748
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://securitytracker.com/id?1010353
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.oliverkarow.de/research/sambar.txt
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.osvdb.org/6585
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.securityfocus.com/bid/10444
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16287
Source: af854a3a-2127-422b-91ae-364da2661108

12 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
7.7%
92th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

sambar