peter bassill · operator
$ cve CVE-2004-2287 JSON

CVE-2004-2287 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.72% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
dsmlight web file browser

Public exploits

SourceTitleDate
exploit-dbdsm light Web file browser 2.0 - Directory Traversal2004-05-18

References

→ the Explorer  ·  watch your stack  ·  NVD