CVE

Id
2262  
CVE No.
CVE-2000-0686  
Status
Candidate  
Description
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.  
Phase
Proposed (20000921)  
Votes
ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  
Comments
Frech> XF:cgi-auction-weaver-read-files | Frech> XF:cgi-auction-weaver-read-files(5150)