BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/archive/1/180506 | Patch Vendor Advisory | 
| http://www.securityfocus.com/bid/2676 | Exploit Vendor Advisory | 
| http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2001-06-26 21:00
Updated : 2008-09-05 13:24
NVD link : CVE-2001-0452
Mitre link : CVE-2001-0452
JSON object : View
CWE
                Products Affected
                brs
- webweaver
 


