Unrated severityNVD Advisory· Published Sep 9, 2013· Updated Apr 29, 2026
CVE-2013-4900
CVE-2013-4900
Description
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request.
Affected products
2cpe:2.3:a:twilightcms:twilight_cms:5.17:*:*:en:*:*:*:*+ 1 more
- cpe:2.3:a:twilightcms:twilight_cms:5.17:*:*:en:*:*:*:*
- cpe:2.3:a:twilightcms:twilight_cms:5.17:*:*:ru:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- archives.neohapsis.com/archives/bugtraq/2013-08/0126.htmlnvdExploit
- www.exploit-db.com/exploits/27777nvdExploit
- www.htbridge.com/advisory/HTB23167nvdExploit
- secunia.com/advisories/54404nvdVendor Advisory
News mentions
0No linked articles in our index yet.