Back

CVE-2001-0871

Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

Published: Dec 21, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (12)

Vendor Product Version
alchemy_lab alchemy_eye 2.0
alchemy_lab alchemy_eye 2.1
alchemy_lab alchemy_eye 2.2
alchemy_lab alchemy_eye 2.3
alchemy_lab alchemy_eye 2.4
alchemy_lab alchemy_eye 2.5
alchemy_lab alchemy_eye 2.6
alchemy_lab alchemy_eye 2.6.18
alchemy_lab alchemy_eye 2.6.19
alchemy_lab alchemy_eye 3.0
alchemy_lab alchemy_eye 3.0.10
dek_software alchemy_network_monitor *

GitHub Security Advisory GHSA-f7cg-5fjp-j936

Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.97%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub