{"api_version":"1","generated_at":"2026-07-23T06:56:48+00:00","cve":"CVE-2004-0059","urls":{"html":"https://cve.report/CVE-2004-0059","api":"https://cve.report/api/cve/CVE-2004-0059.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0059","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0059"},"summary":{"title":"CVE-2004-0059","description":"Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-02-17 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1008779","name":"http://www.securitytracker.com/id?1008779","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WWW File Share Pro Lets Remote Authenticated Users Overwrite Files on the System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=107411794303201&w=2","name":"http://marc.info/?l=bugtraq&m=107411794303201&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Multiple vulnerabilities in WWW Fileshare Pro <= 2.42' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0059","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0059","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"59","vulnerable":"1","versionEndIncluding":"2.42","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lionmax_software","cpe5":"www_file_share_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:01:23.621Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040114 Multiple vulnerabilities in WWW Fileshare Pro <= 2.42","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=107411794303201&w=2"},{"name":"1008779","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1008779"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-01-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040114 Multiple vulnerabilities in WWW Fileshare Pro <= 2.42","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=107411794303201&w=2"},{"name":"1008779","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1008779"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0059","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040114 Multiple vulnerabilities in WWW Fileshare Pro <= 2.42","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=107411794303201&w=2"},{"name":"1008779","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1008779"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0059","datePublished":"2004-01-15T05:00:00.000Z","dateReserved":"2004-01-14T00:00:00.000Z","dateUpdated":"2024-08-08T00:01:23.621Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-02-17 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lionmax_software:www_file_share_pro:*:*:*:*:*:*:*:*","versionEndIncluding":"2.42","matchCriteriaId":"93DF123F-2856-4DB2-96A3-FAF56A6856B7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"59","Ordinal":"1","Title":"CVE-2004-0059","CVE":"CVE-2004-0059","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"59","Ordinal":"1","NoteData":"Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.","Type":"Description","Title":"CVE-2004-0059"},{"CveYear":"2004","CveId":"59","Ordinal":"2","NoteData":"2004-01-15","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"59","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}