Vulnerabilities > CVE-2000-0664 - Unspecified vulnerability in Analogx Simpleserver WWW 1.0.6

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
analogx
nessus
exploit available

Summary

AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.

Vulnerable Configurations

Part Description Count
Application
Analogx
1

Exploit-Db

descriptionAnalogX SimpleServer:WWW 1.0.6 Directory Traversal Vulnerability. CVE-2000-0664. Remote exploit for windows platform
idEDB-ID:20103
last seen2016-02-02
modified2000-07-26
published2000-07-26
reporterFoundstone Inc.
sourcehttps://www.exploit-db.com/download/20103/
titleanalogx simpleserver:www 1.0.6 - Directory Traversal Vulnerability

Nessus

NASL familyWeb Servers
NASL idANALOGX_TRAVERSAL.NASL
descriptionThe remote host is running a version of the AnalogX SimpleServer web server that is affected by a directory traversal vulnerability. An attacker could exploit this in order to read arbitrary files in the context of the affected server.
last seen2020-06-01
modified2020-06-02
plugin id10489
published2000-08-06
reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10489
titleAnalogX SimpleServer:WWW Encoded Traversal Arbitrary File Access