Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) “..” (dot dot backslash)
Source: (2) “”../”” (dot dot slash)
Reference (s):
- (3) “”/%2E%2E%5C”” (encoded dot dot backslash)
- or (4) “”%2E%2E%2F”” (encoded dot dot slash).”
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1496
- BUGTRAQ:20041102 Multiple Vulnerabilities in Web Forums Server
- URL: http://marc.info/?l=bugtraq&m=109943267328552&w=2

