PT-2003-1279 · Brs · Brs Webweaver Web Server
Published
2003-03-18
·
Updated
2008-09-05
·
CVE-2002-1546
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BRS WebWeaver Web Server version 1.01
Description
The issue allows remote attackers to bypass password protections for files and directories. This is achieved via an HTTP request containing a "/./" sequence.
Recommendations
For BRS WebWeaver Web Server version 1.01, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, avoid using password protections that rely on directory traversal mechanisms.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brs Webweaver Web Server