PT-2003-1279 · Brs · Brs Webweaver Web Server

Publicado

2003-03-18

·

Atualizado

2008-09-05

·

CVE-2002-1546

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BRS WebWeaver Web Server version 1.01
Description The issue allows remote attackers to bypass password protections for files and directories. This is achieved via an HTTP request containing a "/./" sequence.
Recommendations For BRS WebWeaver Web Server version 1.01, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, avoid using password protections that rely on directory traversal mechanisms.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1546

Produtos afetados

Brs Webweaver Web Server