PT-2001-1455 · Biblioweb · Biblioweb

Published

2001-03-09

·

Updated

2017-07-12

·

CVE-2001-0226

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BiblioWeb web server version 2.0
Description The issue allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request. This is due to a directory traversal vulnerability.
Recommendations For version 2.0, update to a version that fixes this issue, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0226

Affected Products

Biblioweb