5
CVSSv2

CVE-2001-1010

Published: 22/07/2001 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in pagecount CGI script in Sambar Server prior to 5.0 beta 5 allows remote malicious users to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sambar sambar server 5.0

sambar sambar server 4.4

Exploits

source: wwwsecurityfocuscom/bid/3091/info Sambar Server is a multi-threaded HTTP server for Microsoft Windows and Unix systems Sambar WWW Server is bundled with a sample script('pagecount') which creates temporary files on the host However, it is possible for a remote attacker to craft a web request which will cause pagecount to overwr ...