Vulnerabilities > CVE-2001-1010 - Unspecified vulnerability in Sambar Server 4.4/5.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
sambar
nessus
exploit available

Summary

Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.

Vulnerable Configurations

Part Description Count
Application
Sambar
5

Exploit-Db

descriptionSambar Server 4.4/5.0 pagecount File Overwrite Vulnerability. CVE-2001-1010. Remote exploits for multiple platform
idEDB-ID:21026
last seen2016-02-02
modified2001-07-22
published2001-07-22
reporterkyprizel
sourcehttps://www.exploit-db.com/download/21026/
titleSambar Server 4.4/5.0 pagecount File Overwrite Vulnerability

Nessus

NASL familyCGI abuses
NASL idSAMBAR_PAGECOUNT.NASL
descriptionBy default, there is a pagecount script with Sambar Web Server located at http://sambarserver/session/pagecount This counter writes its temporary files in c:\sambardirectory\tmp. It allows to overwrite any files on the filesystem since the
last seen2020-06-01
modified2020-06-02
plugin id10711
published2001-07-29
reporterThis script is Copyright (C) 2001-2018 Vincent Renardias
sourcehttps://www.tenable.com/plugins/nessus/10711
titleSambar Server pagecount CGI Traversal Arbitrary File Overwrite