CVE-2003-1168

HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.

Scoring

CVSS base score
0.02
EPSS probability
0.41%
Published
2005-05-10
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs