CVE

Id
3370  
CVE No.
CVE-2001-0557  
Status
Candidate  
Description
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a ".." (dot dot) attack which is URL encoded (%2e%2e).  
Phase
Modified (20050509)  
Votes
ACCEPT(2) Frech, Ziese | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Bishop  
Comments