CVE

CVE-2001-0557

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/08/2001
Last modified:
19/12/2017

Description

T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:t._hauck:jana_web_server:*:*:*:*:*:*:*:* 1.46 (including)
cpe:2.3:a:t._hauck:jana_web_server:1.0j:*:*:*:*:*:*:*
cpe:2.3:a:t._hauck:jana_web_server:1.45:*:*:*:*:*:*:*
cpe:2.3:a:t._hauck:jana_web_server:2.0_beta_1:*:*:*:*:*:*:*