peter bassill · operator
$ cve CVE-2001-0224 JSON

CVE-2001-0224 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS7.32% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2001-06-02
Last modified2026-06-16

Affected (1)

VendorProduct
brightstationmuscat empower

Public exploits

SourceTitleDate
exploit-dbBrightstation Muscat 1.0 - Full Path Disclosure2001-02-12

References

→ the Explorer  ·  watch your stack  ·  NVD