Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-2121. PoCs published by Rafel Ivgi The-Insider.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Borland Web Server for Corel Paradox, allowing remote attackers to access files outside the web root directory using encoded or repeated dot-dot-slash sequences.
Description
Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Borland Web Server for Corel Paradox, allowing remote attackers to access files outside the web root directory using encoded or repeated dot-dot-slash sequences.