CVE-1999-0915

URL Live! - Unauthenticated Path Traversal via Dot-Dot Attack

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0915. PoCs published by UNYUN.

AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in URL Live! free webserver. It explains how an attacker can use '../' sequences to access files outside the web root.

Description

URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Exploits (1)

exploitdb WRITEUP VERIFIED
by UNYUN · textremotewindows
https://www.exploit-db.com/exploits/19568

This is a writeup describing a directory traversal vulnerability in URL Live! free webserver. It explains how an attacker can use '../' sequences to access files outside the web root.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: URL Live! free webserver (version not specified)
No auth needed
Prerequisites: Network access to the target webserver
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/746
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/1129

Scores

EPSS 0.0263
EPSS Percentile 83.5%

Details

Status published
Products (1)
pacific_software/url_live 1.0
Published Oct 28, 1999
Tracked Since Feb 18, 2026