VYPR
Unrated severityNVD Advisory· Published Dec 21, 2001· Updated Jun 16, 2026

CVE-2001-0870

CVE-2001-0870

Description

HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Alchemy Lab/Alchemy Eyellm-fuzzy10 versions
    <=2.6.18+ 9 more
    • (no CPE)range: <=2.6.18
    • cpe:2.3:a:alchemy_lab:alchemy_eye:1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:alchemy_lab:alchemy_eye:2.6.18:*:*:*:*:*:*:*
  • <=2.6.18+ 1 more
    • (no CPE)range: <=2.6.18
    • cpe:2.3:a:dek_software:alchemy_network_monitor:*:*:*:*:*:*:*:*range: <=2.6.18

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.