5
CVSSv2

CVE-2001-0571

Published: 22/08/2001 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus prior to 3.0.4 allows remote malicious users to read arbitrary files via a .. (dot dot) in the requested URL.

Vulnerable Product Search on Vulmon Subscribe to Product

elron im anti virus 3.0.3

elron im message inspector 3.0.3

Exploits

source: wwwsecurityfocuscom/bid/2519/info Elron IM is a suite of tools providing internet filtering, virus protection, and other features Certain non-current versions of products in the Internet Manager suite, including IM Anti-Virus, are vulnerable to directory traversal attacks An attacker can compose a long path which includes '/ ...