CVE-2004-2640
LinuxStat < 2.3.1 - Directory Traversal via Template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2640. PoCs published by anonymous.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in LinuxStat versions prior to 2.3.1, allowing attackers to read arbitrary files via '../' sequences in the 'template' parameter. No actual exploit code is present, only a description and example URI.
Description
Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.
Exploits (1)
The provided text describes a directory traversal vulnerability in LinuxStat versions prior to 2.3.1, allowing attackers to read arbitrary files via '../' sequences in the 'template' parameter. No actual exploit code is present, only a description and example URI.