Back
CVE-2004-1444
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CWE-22
CVSS Metrics
Affected Products (46)
| Vendor | Product | Version |
|---|---|---|
| roundup-tracker | roundup | * |
| roundup-tracker | roundup | 0.1.0 |
| roundup-tracker | roundup | 0.1.1 |
| roundup-tracker | roundup | 0.1.2 |
| roundup-tracker | roundup | 0.1.3 |
| roundup-tracker | roundup | 0.2.0 |
| roundup-tracker | roundup | 0.2.1 |
| roundup-tracker | roundup | 0.2.2 |
| roundup-tracker | roundup | 0.2.3 |
| roundup-tracker | roundup | 0.2.4 |
| roundup-tracker | roundup | 0.2.5 |
| roundup-tracker | roundup | 0.2.6 |
| roundup-tracker | roundup | 0.2.7 |
| roundup-tracker | roundup | 0.2.8 |
| roundup-tracker | roundup | 0.3.0 |
| roundup-tracker | roundup | 0.3.0 |
| roundup-tracker | roundup | 0.3.0 |
| roundup-tracker | roundup | 0.3.0 |
| roundup-tracker | roundup | 0.4.0 |
| roundup-tracker | roundup | 0.4.0 |
…and 26 more
GitHub Security Advisory GHSA-q7mf-hp9m-cx6f
Roundup Directory traversal vulnerability
pip
Roundup
<= 0.6.4
Fixed: 0.7.3
References (14)
- http://packetstormsecurity.nl/0406-exploits/roundUP.txt Exploit
- http://secunia.com/advisories/11801/ Exploit, Patch, Vendor Advisory
- http://securitytracker.com/id?1010415
- http://sourceforge.net/tracker/index.php?func=detail&aid=961511&group_id=31577&atid=402788
- http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml Patch
- http://www.securityfocus.com/bid/10495 Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16350
- http://packetstormsecurity.nl/0406-exploits/roundUP.txt Exploit
- http://secunia.com/advisories/11801/ Exploit, Patch, Vendor Advisory
- http://securitytracker.com/id?1010415
- http://sourceforge.net/tracker/index.php?func=detail&aid=961511&group_id=31577&atid=402788
- http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml Patch
- http://www.securityfocus.com/bid/10495 Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16350
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
8.79%
Top 5% most likely to be exploited
Threat Score
22.6 / 100
Data Sources
NVD
EPSS
GitHub