5
CVSSv2

CVE-2001-0205

Published: 03/05/2001 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in AOLserver 3.2 and previous versions allows remote malicious users to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

aol aol server 3.2

Exploits

source: wwwsecurityfocuscom/bid/2343/info It is possible for a remote user to gain read access to directories outside the root directory of an AOLserver Requesting a specially crafted URL composed of '/' sequences will disclose an arbitrary directory target//[file outside web root] ...