{"id":"CVE-2002-1390","details":"The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL.","modified":"2026-04-10T03:34:41.367287Z","published":"2003-01-17T05:00:00Z","references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2003/dsa-223"},{"type":"FIX","url":"http://www.debian.org/security/2003/dsa-223"},{"type":"WEB","url":"http://cristal.inria.fr/~ddr/GeneWeb/en/version/4.09.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/6549"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11021"}],"schema_version":"1.7.5"}