Vulnerabilities (CVE)

Filtered by vendor Intranet-server Subscribe
Filtered by product Localweb2000
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1353 1 Intranet-server 1 Localweb2000 2024-02-04 5.0 MEDIUM N/A
LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.
CVE-2001-0189 1 Intranet-server 1 Localweb2000 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.
CVE-2002-0897 1 Intranet-server 1 Localweb2000 2024-02-04 7.5 HIGH N/A
LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./" directory.