CVE-2004-2287 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 86)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.72% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| dsm | light web file browser |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | dsm light Web file browser 2.0 - Directory Traversal | 2004-05-18 |
→ the Explorer · watch your stack · NVD