Vulnerabilities > CVE-2001-0804 - Unspecified vulnerability in Valerie Mates Interactive Story 1.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files via a .. (dot dot) attack on the "next" parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Interactive Story 1.3 Directory Traversal Vulnerability. CVE-2001-0804. Remote exploit for cgi platform |
id | EDB-ID:21008 |
last seen | 2016-02-02 |
modified | 2001-07-15 |
published | 2001-07-15 |
reporter | qDefense |
source | https://www.exploit-db.com/download/21008/ |
title | interactive story 1.3 - Directory Traversal Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | STORY.NASL |
description | By requesting : GET /cgi-bin/story.pl?next=../../../file_to_read%00 An attacker may use this flaw to read arbitrary files on this server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10817 |
published | 2001-12-03 |
reporter | This script is Copyright (C) 2001-2018 Alert4Web.com |
source | https://www.tenable.com/plugins/nessus/10817 |
title | Interactive Story story.pl next Parameter Traversal Arbitrary File Access |
code |
|
References
- http://www.osvdb.org/683
- http://www.osvdb.org/683
- http://www.securityfocus.com/archive/1/4.3.2.7.2.20010715184257.00b20100%40compumodel.com
- http://www.securityfocus.com/archive/1/4.3.2.7.2.20010715184257.00b20100%40compumodel.com
- http://www.securityfocus.com/bid/3028
- http://www.securityfocus.com/bid/3028
- http://www.valeriemates.com/story_download.html
- http://www.valeriemates.com/story_download.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6843
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6843