5
CVSSv2

CVE-2001-0228

Published: 03/05/2001 Updated: 20/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in GoAhead web server 2.1 and previous versions allows remote malicious users to read arbitrary files via a .. attack in an HTTP GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

goahead software goahead webserver v.2.0

goahead software goahead webserver v.2.1

Exploits

source: wwwsecurityfocuscom/bid/2334/info A specially crafted URL composed of '\' sequences along with the known filename will disclose the requested file This vulnerability will also allow an attacker to execute arbitrary code with root privileges Gaining access to a known file: target/\\\\\\filename Executing ...