20010525 Advisory for Freestyle Chat servermailing list
http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html CVE-2001-0615
faust Informatics FreeStyle chat 4.1 sr2 - Directory Traversal
Record summary
CVE-2001-0615 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBfaust Informatics FreeStyle chat 4.1 sr2 - Directory TraversalExploitDB exploitby nemesystmNot analyzed1 file
References
51841vdb entry
http://www.osvdb.org/1841 2776vdb entry
http://www.securityfocus.com/bid/2776 freestyle-chat-directory-traversal(6601)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6601 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0615