Back

CVE-2003-1166

Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

Published: Dec 31, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
http_commander http_commander 4.0

GitHub Security Advisory GHSA-3fp6-x3rc-h83r

Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 7.10%

Top 6% most likely to be exploited

Threat Score 22.1 / 100

Data Sources

NVD EPSS GitHub