Vulnerability Description
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Brs | Webweaver | 0.49_beta |
References
- http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html
- http://www.securityfocus.com/archive/1/180506PatchVendor Advisory
- http://www.securityfocus.com/bid/2676ExploitVendor Advisory
- http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html
- http://www.securityfocus.com/archive/1/180506PatchVendor Advisory
- http://www.securityfocus.com/bid/2676ExploitVendor Advisory
FAQ
What is CVE-2001-0452?
CVE-2001-0452 is a vulnerability with a CVSS score of 5.0 (MEDIUM). BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.
How severe is CVE-2001-0452?
CVE-2001-0452 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0452?
Check the references section above for vendor advisories and patch information. Affected products include: Brs Webweaver.