CVE-2002-1837 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)
Patch early
A public exploit exists.
Description
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.94% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ids | ids |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Image Display System 0.8.1 - Directory Existence Disclosure | 2002-05-28 |
References
- http://ids.sourceforge.net/ChangeLog.html
- http://online.securityfocus.com/archive/1/274433
- http://www.iss.net/security_center/static/9201.php
- http://www.securityfocus.com/bid/4870
- http://ids.sourceforge.net/ChangeLog.html
- http://online.securityfocus.com/archive/1/274433
- http://www.iss.net/security_center/static/9201.php
- http://www.securityfocus.com/bid/4870
→ the Explorer · watch your stack · NVD