Vulnerabilities > CVE-2002-2145 - Unspecified vulnerability in Savant Webserver

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
savant
exploit available

Summary

Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename.

Vulnerable Configurations

Part Description Count
Application
Savant
1

Exploit-Db

descriptionSavant Webserver 3.1 File Disclosure Vulnerability. CVE-2002-2145. Remote exploit for windows platform
idEDB-ID:21794
last seen2016-02-02
modified2002-09-13
published2002-09-13
reporterAuriemma Luigi
sourcehttps://www.exploit-db.com/download/21794/
titleSavant Webserver 3.1 File Disclosure Vulnerability