Search

published date: December 31, 2004

CVE-2004-2121 : Directory Traversal Vulnerability

Description

Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.

Product(s):

  • Borland Software Web Server for Corel Paradox

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-2121, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-2121 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?