CVE-2003-1414
Darwin Streaming Server 4.1.2 and QuickTime Streaming Server 4.1.1 - Path Traversal via Filename Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1414. PoCs published by Joe Testa.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in QuickTime/Darwin Streaming Server's parse_xml.cgi script to retrieve arbitrary files. The PoC demonstrates accessing the qtusers file by manipulating the filename parameter.
Description
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
Exploits (1)
This exploit leverages a directory traversal vulnerability in QuickTime/Darwin Streaming Server's parse_xml.cgi script to retrieve arbitrary files. The PoC demonstrates accessing the qtusers file by manipulating the filename parameter.