ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker...
Vulnerability Description
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-0555
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.kb.cert.org/vuls/id/795707
- http://www01.screamingmedia.com/en/security/sms1001.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6689
- http://www.osvdb.org/13887
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0166.html
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0165.html
- http://www.securityfocus.com/bid/2869
Affected Vendor
screaming media
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.