10
CVSSv2

CVE-2001-1586

Published: 12/02/2010 Updated: 17/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in SimpleServer:WWW 1.13 and previous versions allows remote malicious users to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664.

Vulnerable Product Search on Vulmon Subscribe to Product

analogx simpleserver www 1.06

analogx simpleserver www 1.05

analogx simpleserver www 1.04

analogx simpleserver www 1.03

analogx simpleserver www 1.01

analogx simpleserver www 1.0.8

analogx simpleserver www

Exploits

source: wwwsecurityfocuscom/bid/3112/info SimpleServer:WWW is a freely available HTTP daemon available from AnalogX It is designed for simplicity of operation A problem with the web server could allow a remote user to execute arbitrary commands, and potentially gain local access to the system The problem is in the validation of URLs t ...