Back
CVE-2003-1166
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.
Published: Dec 31, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| http_commander | http_commander | 4.0 |
GitHub Security Advisory GHSA-3fp6-x3rc-h83r
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0...
References (10)
- http://secunia.com/advisories/10125 Exploit
- http://www.http-com.com/Default.asp?section=Features
- http://www.osvdb.org/2780
- http://www.securityfocus.com/bid/8948 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13622
- http://secunia.com/advisories/10125 Exploit
- http://www.http-com.com/Default.asp?section=Features
- http://www.osvdb.org/2780
- http://www.securityfocus.com/bid/8948 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13622
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
7.10%
Top 6% most likely to be exploited
Threat Score
22.1 / 100
Data Sources
NVD
EPSS
GitHub