VulnerabilityModified
CVE-2001-0253
Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a ..
MEDIUM 5.0EPSS 10.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 10.64% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- iweb systems/hyperseek
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-01/0463.htmlExploit, Vendor Advisory
- http://www.kb.cert.org/vuls/id/146704US Government Resource
- http://www.securityfocus.com/bid/2314Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6012
- http://archives.neohapsis.com/archives/bugtraq/2001-01/0463.htmlExploit, Vendor Advisory
- http://www.kb.cert.org/vuls/id/146704US Government Resource
- http://www.securityfocus.com/bid/2314Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6012
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.