5
CVSSv2

CVE-2001-0224

Published: 02/06/2001 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Muscat Empower CGI program allows remote malicious users to obtain the absolute pathname of the server via an invalid request in the DB parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

brightstation muscat empower 1.0

Exploits

source: wwwsecurityfocuscom/bid/2374/info Making an invalid request to a machine running Brightstation Muscat, will disclose the physical path to the root directory target/cgi-bin/empower?DB=UkRteamHole target/cgi-bin/empower?DB=UkRteamHole ...