Record summary

CVE-2001-0555 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSiteWare 2.5/3.0/3.1 Editor Desktop - Directory TraversalExploitDB exploitby Foundstone LabsNot analyzed1 file
ExploitDB

PoC details

References

8