CVE-2015-1002

Published Oct 25, 2015

Last updated 9 years ago

Overview

Description
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.
Source
ics-cert@hq.dhs.gov
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
6.4
Impact score
4.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Evaluator

Comment
<a href="https://cwe.mitre.org/data/definitions/177.html">CWE-177: Improper Handling of URL Encoding (Hex Encoding)</a>
Impact
-
Solution
-

Configurations