20000510 KNapster Vulnerability Compromises User-readable Filesmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html CVE-2000-0412
John Donoghue Knapster 0.9/1.3.8 - File Access
Record summary
CVE-2000-0412 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJohn Donoghue Knapster 0.9/1.3.8 - File AccessExploitDB exploitby no_maamNot analyzed1 file
References
420000510 Gnapster Vulnerability Compromises User-readable Filesmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html 1186vdb entry
http://www.securityfocus.com/bid/1186 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0412