PT-2001-2091 · Persits · Aspupload
Published
2001-11-30
·
Updated
2016-10-18
·
CVE-2001-0938
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AspUpload version 2.1
Description
A directory traversal issue allows remote attackers to upload and read arbitrary files, and list arbitrary directories, by using a .. (dot dot) in the
Filename parameter in certain scripts, such as "UploadScript11.asp" or "DirectoryListing.asp".Recommendations
For AspUpload version 2.1, consider restricting access to the
UploadScript11.asp and DirectoryListing.asp scripts until a fix is available, and avoid using the Filename parameter with unvalidated input to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aspupload