7.5
CVSSv2

CVE-2001-0626

Published: 22/08/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

O'Reilly Website Professional 2.5.4 and previous versions allows remote malicious users to determine the physical path to the root directory via a URL request containing a ":" character.

Vulnerable Product Search on Vulmon Subscribe to Product

oreilly website professional

Exploits

source: wwwsecurityfocuscom/bid/2488/info Requesting a specially crafted URL to a machine running O'Reilly & Associates Website Professional, will disclose the physical path to the root directory wwwexamplecom/:/ ...