CVE-2001-0561
Drummond Miles A1Stats < 1.6 - Directory Traversal via Dot-Dot Attack in CGI Scripts
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2001-0561. PoCs published by neme-dhc.
AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in A1Stats CGI script. The vulnerability allows an attacker to access files outside the intended directory tree by using '/../' sequences in the querystring.
Description
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.
Exploits (3)
This is a writeup describing a directory traversal vulnerability in A1Stats CGI script. The vulnerability allows an attacker to access files outside the intended directory tree by using '/../' sequences in the querystring.
The exploit describes a directory traversal vulnerability in A1Stats CGI script, allowing attackers to access sensitive files outside the intended directory via '/../' sequences in the querystring. It also mentions the potential to overwrite files by appending echo commands.
The exploit describes a directory traversal vulnerability in A1Stats CGI script, allowing attackers to access sensitive system files via '/../' sequences in the querystring. It also mentions the potential to overwrite files by appending echo commands.