CVE-2001-0212
HIS Auktion 1.62 - Directory Traversal and Arbitrary File Read via Menue Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0212. PoCs published by cuctema.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in HIS Software Auktion 1.62, allowing an attacker to read arbitrary files outside the web root by manipulating the 'menue' parameter with '../' sequences. The PoC includes example URLs to disclose system files like '/etc/passwd'.
Description
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in HIS Software Auktion 1.62, allowing an attacker to read arbitrary files outside the web root by manipulating the 'menue' parameter with '../' sequences. The PoC includes example URLs to disclose system files like '/etc/passwd'.