VYPR

Double Choco Latte

by Dcl

CVEs (2)

  • CVE-2002-1038Oct 4, 2002
    risk 0.00cvss epss 0.01

    Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.

  • CVE-2002-1039Oct 4, 2002
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature.