Vulnerabilities > CVE-2001-0466 - Directory Traversal vulnerability in Microburst Ustorekeeper Online Shopping System 1.61

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
microburst
nessus
exploit available

Summary

Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Vulnerable Configurations

Part Description Count
Application
Microburst
1

Exploit-Db

descriptionMicroburst uStorekeeper 1.x Remote Arbitrary Commands Vulnerability. CVE-2001-0466. Remote exploit for cgi platform
idEDB-ID:20725
last seen2016-02-02
modified2001-04-02
published2001-04-02
reporterUkR hacking team
sourcehttps://www.exploit-db.com/download/20725/
titleMicroburst uStorekeeper 1.x - Remote Arbitrary Commands Vulnerability

Nessus

NASL familyCGI abuses
NASL idUSTOREKEEPER.NASL
descriptionThe
last seen2020-06-01
modified2020-06-02
plugin id10645
published2001-04-03
reporterThis script is Copyright (C) 2001-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10645
titleuStorekeeper ustorekeeper.pl file Parameter Traversal Arbitrary File Access