PT-2001-2091 · Persits · Aspupload

Published

2001-11-30

·

Updated

2016-10-18

·

CVE-2001-0938

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions AspUpload version 2.1
Description A directory traversal issue allows remote attackers to upload and read arbitrary files, and list arbitrary directories, by using a .. (dot dot) in the Filename parameter in certain scripts, such as "UploadScript11.asp" or "DirectoryListing.asp".
Recommendations For AspUpload version 2.1, consider restricting access to the UploadScript11.asp and DirectoryListing.asp scripts until a fix is available, and avoid using the Filename parameter with unvalidated input to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0938

Affected Products

Aspupload