Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via “@” (at) characters in a CD (CWD) command, such as
(1) “@/….\”,
(2) “@@@/..c:\”, or
(3) “@/..@/..”.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2233
Reference (s):
- BUGTRAQ:20021219 Multiple vulnerabilities in Enceladus Server
- URL:http://archives.neohapsis.com/archives/bugtraq/2002-12/0193.html
- XF:enceladus-cd-directory-traversal(11019)
- URL:https://exchange.xforce.ibmcloud.com/vulnerabilities/11019
- XF:enceladus-cd-dos(11020)
- URL:https://exchange.xforce.ibmcloud.com/vulnerabilities/11020