CVE-2001-0452 describes a full path disclosure vulnerability in BRS WebWeaver FTP server versions prior to 0.64 Beta. An unauthenticated remote attacker can exploit this by sending a "CD *" command followed by an "ls" command, revealing the server's real pathname. This vulnerability has a medium severity CVSS score of 5.0, indicating low attack complexity and potential for information disclosure (confidentiality impact). While there is no evidence of active exploitation, an exploit is publicly available on ExploitDB, and there is no significant community discussion or media coverage surrounding this old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.49_betaCPE matchmatch criteria | cpe:2.3:a:brs:webweaver:0.49_beta:*:*:*:*:*:*:* | ||
0.50_betaCPE matchmatch criteria | cpe:2.3:a:brs:webweaver:0.50_beta:*:*:*:*:*:*:* | ||
0.51_betaCPE matchmatch criteria | cpe:2.3:a:brs:webweaver:0.51_beta:*:*:*:*:*:*:* | ||
0.52_betaCPE matchmatch criteria | cpe:2.3:a:brs:webweaver:0.52_beta:*:*:*:*:*:*:* | ||
0.60_betaCPE matchmatch criteria | cpe:2.3:a:brs:webweaver:0.60_beta:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.