Directory Traversal Vulnerability in Cisco IDS Device Manager
CVE-2002-0908

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
4 October 2002

Summary

A directory traversal vulnerability exists in the web server component of Cisco IDS Device Manager prior to version 3.1.2. This flaw allows remote attackers to manipulate HTTP requests to gain unauthorized access to arbitrary files on the server by exploiting the '..' (dot dot) sequence in the URL, potentially leading to the exposure of sensitive information and system files.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.