Vulnerabilities > CVE-2001-0224 - Path Disclosure vulnerability in Brightstation Muscat Empower 1.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
brightstation
nessus
exploit available

Summary

Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.

Vulnerable Configurations

Part Description Count
Application
Brightstation
1

Exploit-Db

descriptionBrightstation Muscat 1.0 Root Path Disclosure Vulnerability. CVE-2001-0224. Remote exploit for cgi platform
idEDB-ID:20633
last seen2016-02-02
modified2001-02-12
published2001-02-12
reportercuctema
sourcehttps://www.exploit-db.com/download/20633/
titleBrightstation Muscat 1.0 Root Path Disclosure Vulnerability

Nessus

NASL familyCGI abuses
NASL idEMPOWER_PATH.NASL
descriptionThe remote host appears to be running Muscat Empower. It was possible to get the physical location of a virtual web directory by issuing the following command : GET /cgi-bin/empower?DB=whatever HTTP/1.0 A remote attacker could use this information to mount further attacks.
last seen2020-06-01
modified2020-06-02
plugin id10609
published2001-02-13
reporterThis script is Copyright (C) 2001-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10609
titleMuscat Empower CGI Malformed DB Parameter Path Disclosure