First published: Tue Dec 19 2000(Updated: )
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BTCPayServer | <=0.94.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0920 is considered a high severity vulnerability due to its potential for remote exploitation and unauthorized access to sensitive files.
The vulnerability affects BOA web server version 0.94.8.2 and earlier versions.
To fix CVE-2000-0920, upgrade the BOA web server to a version later than 0.94.8.2.
CVE-2000-0920 is associated with a directory traversal attack that allows attackers to access arbitrary files on the server.
Yes, CVE-2000-0920 can lead to unauthorized data exposure, allowing attackers to read sensitive files on the server.