Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.
| Software | From | Fixed in |
|---|---|---|
| brs / webweaver | 0.50_beta | 0.50_beta.x |
| brs / webweaver | 0.60_beta | 0.60_beta.x |
| brs / webweaver | 0.52_beta | 0.52_beta.x |
| brs / webweaver | 0.51_beta | 0.51_beta.x |
| brs / webweaver | 0.62_beta | 0.62_beta.x |
| brs / webweaver | 0.61_beta | 0.61_beta.x |
| brs / webweaver | 0.49_beta | 0.49_beta.x |