{"id":"CVE-2004-1444","aliases":["PYSEC-2026-745"],"url":"https://o3.security/vulnerability/CVE-2004-1444","summary":"Roundup Directory traversal vulnerability","details":"Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via `..` (dot dot) sequences in an `@@` command in an HTTP GET request.","published":"2022-04-29T02:59:35Z","modified":"2026-07-06T08:11:28.382205370Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"PyPI","name":"roundup","fixedVersion":"0.7.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1444"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16350"},{"type":"PACKAGE","url":"https://github.com/roundup-tracker/roundup"},{"type":"WEB","url":"http://packetstormsecurity.nl/0406-exploits/roundUP.txt"},{"type":"WEB","url":"http://secunia.com/advisories/11801"},{"type":"WEB","url":"http://securitytracker.com/id?1010415"},{"type":"WEB","url":"http://sourceforge.net/tracker/index.php?func=detail&aid=961511&group_id=31577&atid=402788"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml"},{"type":"WEB","url":"http://www.securityfocus.com/bid/10495"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-06T08:11:28.382205370Z"}}