CVE-2001-0557 describes a directory traversal vulnerability in T. Hauck Jana Webserver versions 1.46 and earlier. An unauthenticated remote attacker can exploit this flaw by using URL-encoded dot-dot sequences (%2e%2e) to access and view arbitrary files on the server. This vulnerability is rated Medium severity (CVSS 5.0), indicating it can be exploited over the network with low attack complexity, leading to a partial compromise of confidentiality without affecting integrity or availability. The EPSS score is low, suggesting a low probability of exploitation, but the FAUCET Risk Score is high at 95/100. While not listed on the CISA KEV catalog, exploit code for this vulnerability is publicly available on ExploitDB (EDB-20829). There is significant community discussion, with 10 mentions, indicating awareness and interest in this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.46CPE matchmatch criteria | cpe:2.3:a:t._hauck:jana_web_server:*:*:*:*:*:*:*:* | ||
1.0jCPE matchmatch criteria | cpe:2.3:a:t._hauck:jana_web_server:1.0j:*:*:*:*:*:*:* | ||
1.45CPE matchmatch criteria | cpe:2.3:a:t._hauck:jana_web_server:1.45:*:*:*:*:*:*:* | ||
2.0_beta_1CPE matchmatch criteria | cpe:2.3:a:t._hauck:jana_web_server:2.0_beta_1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.