CVE

Id
3033  
CVE No.
CVE-2001-0212  
Status
Candidate  
Description
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.  
Phase
Proposed (20010309)  
Votes
MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese  
Comments
Frech> XF:his-auktion-cgi-url(6090)