7.5
CVSSv2

CVE-2002-2145

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Savant Web Server 3.1 and previous versions allows remote malicious users to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename.

Vulnerable Product Search on Vulmon Subscribe to Product

savant savant webserver

Exploits

source: wwwsecurityfocuscom/bid/5709/info Savant Webserver is vulnerable to an input validation bug, that could allow malicious users access to password protected folders It should be noted that versions below 31 may also be vulnerable to this issue host/password_folder "GET /password_folder / HTTP/10" <-- use with telne ...