PT-2001-1706 · Datawizard · Datawizard Webxq Server

Publicado

2001-06-27

·

Atualizado

2017-10-10

·

CVE-2001-0495

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: DataWizard WebXQ server version 1.204
Description: The issue allows remote attackers to view files outside of the web root via a .. (dot dot) attack, which is a type of directory traversal attack. This attack takes advantage of the fact that the .. notation can be used to access parent directories, potentially allowing access to sensitive files.
Recommendations: For DataWizard WebXQ server version 1.204, consider implementing proper input validation and sanitization to prevent directory traversal attacks, such as restricting access to files outside of the web root and limiting the use of the .. notation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0495

Produtos afetados

Datawizard Webxq Server