CVE

Id
2263  
CVE No.
CVE-2000-0687  
Status
Candidate  
Description
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.  
Phase
Proposed (20000921)  
Votes
ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  
Comments
Frech> XF:cgi-auction-weaver-read-files | Christey> Need to double-check BID"s on all these Auction Weaver prob"s. | Frech> XF:cgi-auction-weaver-read-files(5150)