Record summary

CVE-2001-1344 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBcgiCentral WebStore 400 - Administrator Authentication BypassExploitDB exploitby Igor DobrovitskiNot analyzed1 file
ExploitDB

PoC details

References

4