{"api_version":"1","generated_at":"2026-07-23T04:57:25+00:00","cve":"CVE-2003-1413","urls":{"html":"https://cve.report/CVE-2003-1413","api":"https://cve.report/api/cve/CVE-2003-1413.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1413","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1413"},"summary":{"title":"CVE-2003-1413","description":"parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using \"..\" sequences in the filename parameter and comparing the resulting error messages.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-22","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securityreason.com/securityalert/3260","name":"http://securityreason.com/securityalert/3260","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/313517","name":"http://www.securityfocus.com/archive/1/313517","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6992","name":"http://www.securityfocus.com/bid/6992","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Apple QuickTime/Darwin Streaming Server Remote File Existence Revealing Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11445","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11445","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1413","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1413","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1413","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"darwin_streaming_server","cpe6":"4.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1413","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"quicktime_streaming_server","cpe6":"4.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:28:02.935Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3260","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3260"},{"name":"20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/313517"},{"name":"darwin-dotdot-file-existence(11445)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11445"},{"name":"6992","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6992"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using \"..\" sequences in the filename parameter and comparing the resulting error messages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3260","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3260"},{"name":"20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/313517"},{"name":"darwin-dotdot-file-existence(11445)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11445"},{"name":"6992","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6992"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1413","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using \"..\" sequences in the filename parameter and comparing the resulting error messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3260","refsource":"SREASON","url":"http://securityreason.com/securityalert/3260"},{"name":"20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/313517"},{"name":"darwin-dotdot-file-existence(11445)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11445"},{"name":"6992","refsource":"BID","url":"http://www.securityfocus.com/bid/6992"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1413","datePublished":"2007-10-20T10:00:00.000Z","dateReserved":"2007-10-19T00:00:00.000Z","dateUpdated":"2024-08-08T02:28:02.935Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-22","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:darwin_streaming_server:4.1.2:*:*:*:*:*:*:*","matchCriteriaId":"3F40D1E1-10B3-4A7C-A945-A8D74F3DCB35"},{"vulnerable":true,"criteria":"cpe:2.3:a:apple:quicktime_streaming_server:4.1.1:*:*:*:*:*:*:*","matchCriteriaId":"583E3DC3-86AB-4E91-B464-18FFBC436A82"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1413","Ordinal":"1","Title":"CVE-2003-1413","CVE":"CVE-2003-1413","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1413","Ordinal":"1","NoteData":"parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using \"..\" sequences in the filename parameter and comparing the resulting error messages.","Type":"Description","Title":"CVE-2003-1413"},{"CveYear":"2003","CveId":"1413","Ordinal":"2","NoteData":"2007-10-20","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1413","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}