First published: Mon Feb 07 2000(Updated: )
Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axis 700 Network Document Server | =1.0 | |
Axis 700 Network Document Server | =1.13 | |
Axis 700 Network Document Server | =1.12 | |
Axis 700 Network Document Server | =1.10 | |
Axis 700 Network Document Server | =1.11 | |
Axis 700 Network Document Server | =1.14 | |
=1.0 | ||
=1.10 | ||
=1.11 | ||
=1.12 | ||
=1.13 | ||
=1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0144 is classified as a moderate vulnerability due to its potential to allow unauthorized access to administrator functions.
To fix CVE-2000-0144, ensure proper access controls and URL restrictions are implemented on the Axis 700 Network Document Server.
CVE-2000-0144 affects versions 1.0, 1.10, 1.11, 1.12, 1.13, and 1.14 of the Axis 700 Network Document Server.
CVE-2000-0144 can be exploited using a directory traversal attack, allowing attackers to access protected resources.
Users of the Axis 700 Network Document Server with vulnerable versions may be at risk of unauthorized access to their systems.