CVE-2003-1166
HTTP Commander 4.0 - Directory Traversal via File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1166. PoCs published by Zero X.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in HTTP Commander 4.0, allowing remote attackers to access sensitive files outside the server root using '../' sequences. It includes example URLs demonstrating the exploit but lacks executable code.
Description
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
The provided text describes a directory traversal vulnerability in HTTP Commander 4.0, allowing remote attackers to access sensitive files outside the server root using '../' sequences. It includes example URLs demonstrating the exploit but lacks executable code.