CVE
- Id
- 2411
- CVE No.
- CVE-2000-0842
- Status
- Candidate
- Description
- The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- Phase
- Proposed (20001018)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall
- Comments
- Frech> XF:sco-help-view-files(5226) | Christey> What is the proper "spelling" for the SCO help HTTP server? | I"ve seen it as "SCOhelp" and "scohelphttp" and "SCO help HTTP" | Christey> XF:sco-help-view-files | Christey> typo - extra "