CVE-2001-0211

WebSPIRS 3.1 - Directory Traversal via sp.nextform Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0211. PoCs published by cuctema.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in SilverPlatter WebSPIRS by crafting a URL with '../' sequences to access files outside the root directory. The attack is straightforward and requires no authentication.

Description

Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cuctema · textremotemultiple
https://www.exploit-db.com/exploits/20625

This exploit leverages a directory traversal vulnerability in SilverPlatter WebSPIRS by crafting a URL with '../' sequences to access files outside the root directory. The attack is straightforward and requires no authentication.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: SilverPlatter WebSPIRS
No auth needed
Prerequisites: Known filename and path structure on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-02/0217.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2362

Scores

EPSS 0.0655
EPSS Percentile 92.9%

Details

Status published
Products (1)
silverplatter/webspirs 3.3.1
Published Jun 02, 2001
Tracked Since Feb 18, 2026