Vulnerabilities > CVE-2001-0075 - Unspecified vulnerability in Technote INC Technote 2000/2001/Pro

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
technote-inc
nessus
exploit available

Summary

Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.

Vulnerable Configurations

Part Description Count
Application
Technote_Inc
3

Exploit-Db

descriptionTechnote 2000/2001 'filename' Parameter Command Execution And File Disclosure Vulnerability. CVE-2001-0075. Remote exploit for cgi platform
idEDB-ID:20523
last seen2016-02-02
modified2000-12-27
published2000-12-27
reporterKsecurity
sourcehttps://www.exploit-db.com/download/20523/
titleTechnote 2000/2001 - 'filename' Parameter Command Execution And File Disclosure Vulnerability

Nessus

NASL familyCGI abuses
NASL idTECHNOTE.NASL
descriptionThe technote CGI board is installed. This board has a well known security flaw in the CGI main.cgi that lets an attacker read arbitrary files with the privileges of the http daemon (usually root or nobody).
last seen2020-06-01
modified2020-06-02
plugin id10584
published2000-12-29
reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10584
titleTechnote main.cgi filename Parameter Traversal Arbitrary File Access