Vulnerabilities > CVE-2001-0555 - Unspecified vulnerability in Screaming Media Siteware

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
screaming-media
critical
exploit available

Summary

ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.

Vulnerable Configurations

Part Description Count
Application
Screaming_Media
1

Exploit-Db

descriptionSiteWare 2.5/3.0/3.1 Editor Desktop Directory Traversal Vulnerability. CVE-2001-0555. Webapps exploit for java platform
idEDB-ID:20925
last seen2016-02-02
modified2001-06-13
published2001-06-13
reporterFoundstone Labs
sourcehttps://www.exploit-db.com/download/20925/
titleSiteWare 2.5/3.0/3.1 Editor Desktop Directory Traversal Vulnerability