CVE Database · CVE-2000-0412
CVSS v3.1
N/A
EPSS
2.75%
Published
May 1, 1999
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.
Affected Products (1)
References (8)