PT-2003-1279 · Brs · Brs Webweaver Web Server

Published

2003-03-18

·

Updated

2008-09-05

·

CVE-2002-1546

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BRS WebWeaver Web Server version 1.01
Description The issue allows remote attackers to bypass password protections for files and directories. This is achieved via an HTTP request containing a "/./" sequence.
Recommendations For BRS WebWeaver Web Server version 1.01, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, avoid using password protections that rely on directory traversal mechanisms.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1546

Affected Products

Brs Webweaver Web Server