CVE
- Id
- 2263
- CVE No.
- CVE-2000-0687
- Status
- Candidate
- Description
- Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.
- Phase
- Proposed (20000921)
- Votes
- ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall
- Comments
- Frech> XF:cgi-auction-weaver-read-files | Christey> Need to double-check BID"s on all these Auction Weaver prob"s. | Frech> XF:cgi-auction-weaver-read-files(5150)