CVE-2001-0286
A1 HTTP server 1.0a - Directory Traversal via Dot-Dot in HTTP GET Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0286. PoCs published by slipy.
AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in an unspecified web server. The exploit involves crafting a URL with '../' sequences to access files outside the web root, such as 'Scandisk.log'.
Description
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by slipy · textremotewindows
https://www.exploit-db.com/exploits/20657
This is a writeup describing a directory traversal vulnerability in an unspecified web server. The exploit involves crafting a URL with '../' sequences to access files outside the web root, such as 'Scandisk.log'.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
unspecified web server (likely older versions)
No auth needed
Prerequisites:
network access to the target web server
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html
Scores
EPSS
0.0301
EPSS Percentile
85.7%
Details
Status
published
Products (1)
a1webserver/http_server
1.0
Published
May 03, 2001
Tracked Since
Feb 18, 2026