Vulnerabilities > CVE-2000-1036 - Unspecified vulnerability in Extent Technologies RBS ISP 2.5

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
extent-technologies
nessus
exploit available

Summary

Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter.

Vulnerable Configurations

Part Description Count
Application
Extent_Technologies
1

Exploit-Db

descriptionExtent Technologies RBS ISP 2.5 Directory Traversal Vulnerability. CVE-2000-1036. Remote exploits for multiple platform
idEDB-ID:20234
last seen2016-02-02
modified2000-09-21
published2000-09-21
reporteranon
sourcehttps://www.exploit-db.com/download/20234/
titleextent technologies rbs isp 2.5 - Directory Traversal Vulnerability

Nessus

NASL familyCGI abuses
NASL idRBS.NASL
descriptionThe version of Extent RBS ISP installed on the remote host fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id10521
published2000-09-26
reporterThis script is Copyright (C) 2000-2018 Zorgon <[email protected]>
sourcehttps://www.tenable.com/plugins/nessus/10521
titleExtent RBS Web Server Image Parameter Traversal Arbitrary File Access