Mozilla Firefox < 0.0.9 'Plain Old Webserver' (POW) Directory Traversal Arbitrary File Access (deprecated)

Low Nessus Network Monitor Plugin ID 3910


The remote host is vulnerable to a directory traversal flaw.


The remote host is running Plain Old Webserver (POW), a Firefox plugin that allows the user to run a web server via a browser plugin. This version of POW is vulnerable to a directory traversal flaw. An attacker exploiting this flaw would send a malformed request that contained '../' strings. Such a request would allow the attacker to obtain confidential files from outside the web root directory. Successful exploitation would lead to the loss of confidential data.


Upgrade to version 0.0.9 or higher.

See Also

Plugin Details

Severity: Low

ID: 3910

File Name: 3910.prm

Family: Web Servers

Published: 2007/02/12

Modified: 2016/03/07

Dependencies: 1442

Risk Information

Risk Factor: Low


Base Score: 3.3

Temporal Score: 2.7

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 4.2

Temporal Score: 3.9


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Reference Information

CVE: CVE-2007-0872

BID: 22502

OSVDB: 33174