Unrated severityNVD Advisory· Published Dec 31, 2003· Updated Jun 16, 2026
CVE-2003-1168
CVE-2003-1168
Description
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.
Affected products
1- Range: =4.0
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- secunia.com/advisories/10125nvdExploitPatch
- www.securityfocus.com/bid/8949nvdExploit
News mentions
0No linked articles in our index yet.