CVE
- Id
- 3255
- CVE No.
- CVE-2001-0437
- Status
- Candidate
- Description
- upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.
- Phase
- Interim (20010911)
- Votes
- ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall
- Comments
- Frech> XF:dcforum-az-file-upload(6393)