CVE-2001-0938: Medium severity Persits AspUpload vulnerability
Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0938?
CVE-2001-0938 is considered a high severity vulnerability due to its potential for directory traversal and unauthorized file access.
How do I fix CVE-2001-0938?
To fix CVE-2001-0938, you should upgrade to a more secure version of AspUpload beyond 2.1 and apply proper input validation.
What systems are affected by CVE-2001-0938?
CVE-2001-0938 specifically affects AspUpload 2.1, installed in certain configurations.
Can CVE-2001-0938 be exploited remotely?
Yes, CVE-2001-0938 can be exploited remotely by sending specially crafted requests to the vulnerable AspUpload scripts.
What are the potential impacts of exploiting CVE-2001-0938?
Exploitation of CVE-2001-0938 may allow attackers to read sensitive files and list directory contents, leading to further system compromise.