CVE-2000-0412

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/1999
Last modified:
03/04/2025

Description

The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:napster:knapster:napster:*:*:*:*:*:*:*