10
CVSSv2

CVE-2000-0638

Published: 11/07/2000 Updated: 10/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

bb-hostsvc.sh in Big Brother 1.4h1 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sean macguire big brother 1.0

sean macguire big brother 1.4

sean macguire big brother 1.4g

sean macguire big brother 1.3

sean macguire big brother 1.3b

sean macguire big brother 1.09b

sean macguire big brother 1.09c

sean macguire big brother 1.09d

sean macguire big brother 1.4h

sean macguire big brother 1.4h1

sean macguire big brother 1.1

sean macguire big brother 1.2

Exploits

source: wwwsecurityfocuscom/bid/1455/info Versions 14H and prior of BB4 Big Brother are susceptible to a directory traversal vulnerability which would allow a remote user to view the contents of any directory or file on the system Executing a GET request for: target/cgi-bin/bb-hostsvcsh?HOSTSVC=///directory will display th ...