5
CVSSv2

CVE-2000-0671

Published: 21/07/2000 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Roxen web server earlier than 2.0.69 allows allows remote malicious users to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.

Vulnerable Product Search on Vulmon Subscribe to Product

roxen webserver 2.0.x

Exploits

source: wwwsecurityfocuscom/bid/1510/info If a request containing the null character (%00) is made to the Roxen Web Server, the server will return directory contents, and the source of unparsed scripts and html pages For example, a request to wwwservercom/%00 Will return the contents of the server's document root directory V ...