CVE-2004-2047

Easyweb Filemanager - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/24306

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109068482605241&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/8193
Exploit, Vendor Advisory x_refsource_misc
http://www.cirt.net/advisories/ew_file_manager.shtml
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10792
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16806
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12151

Scores

EPSS 0.0754
EPSS Percentile 91.9%

Details

Status published
Products (1)
easyweb/easyweb_filemanager 1.0_rc1
Published Jul 23, 2004
Tracked Since Feb 18, 2026