Unrated severityNVD Advisory· Published Aug 31, 2001· Updated Apr 16, 2026
CVE-2001-0973
CVE-2001-0973
Description
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.
Affected products
6cpe:2.3:a:fraunhofer_fit:bscw:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:fraunhofer_fit:bscw:*:*:*:*:*:*:*:*range: <=4.0.2_beta
- cpe:2.3:a:fraunhofer_fit:bscw:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:fraunhofer_fit:bscw:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:fraunhofer_fit:bscw:3.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:fraunhofer_fit:bscw:3.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:fraunhofer_fit:bscw:4.0.1_beta:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- archives.neohapsis.com/archives/bugtraq/2001-08/0328.htmlnvdPatchVendor Advisory
- bscw.gmd.de/Bulletins/BSCW-SB-2001-08.extract.txtnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/465971nvdUS Government Resource
- www.iss.net/security_center/static/7029.phpnvd
- www.securityfocus.com/bid/3227nvd
News mentions
0No linked articles in our index yet.