PT-2001-1706 · Datawizard · Datawizard Webxq Server

Published

2001-06-27

·

Updated

2017-10-10

·

CVE-2001-0495

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: DataWizard WebXQ server version 1.204
Description: The issue allows remote attackers to view files outside of the web root via a .. (dot dot) attack, which is a type of directory traversal attack. This attack takes advantage of the fact that the .. notation can be used to access parent directories, potentially allowing access to sensitive files.
Recommendations: For DataWizard WebXQ server version 1.204, consider implementing proper input validation and sanitization to prevent directory traversal attacks, such as restricting access to files outside of the web root and limiting the use of the .. notation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0495

Affected Products

Datawizard Webxq Server