Record summary

CVE-2001-0557 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBT. Hauck Jana Server 1.45/1.46 - Hex Encoded Directory TraversalExploitDB exploitby neme-dhcNot analyzed1 file
ExploitDB

PoC details

References

5