CVE-2013-4900 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier as used in Twilight CMS allows remote attackers to read arbitrary files via a ..5c (dot dot encoded backslash) in a GET request.
Reference
http://archives.neohapsis.com/archives/bugtraq/2013-08/0126.html http://secunia.com/advisories/54404 http://www.exploit-db.com/exploits/27777 https://www.htbridge.com/advisory/HTB23167
Share on: