Vulnerabilities > CVE-2001-1344 - Authentication Bypass vulnerability in Cgicentral Webstore 400 and Webstore 400Cs

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
cgicentral
exploit available

Summary

WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

Vulnerable Configurations

Part Description Count
Application
Cgicentral
2

Exploit-Db

descriptioncgiCentral WebStore 400 Administrator Authentication Bypass Vulnerability. CVE-2001-1344 . Remote exploit for cgi platform
idEDB-ID:20914
last seen2016-02-02
modified2001-05-06
published2001-05-06
reporterIgor Dobrovitski
sourcehttps://www.exploit-db.com/download/20914/
titlecgiCentral WebStore 400 Administrator Authentication Bypass Vulnerability