CVE
- Id
- 3374
- CVE No.
- CVE-2001-0561
- Status
- Candidate
- Description
- Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.
- Phase
- Modified (20050509)
- Votes
- ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop
- Comments
- Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description.