CVE

Id
12504  
CVE No.
CVE-2005-1298  
Status
Candidate  
Description
The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.  
Phase
Assigned (20050426)  
Votes
None (candidate not yet proposed)  
Comments