CVE
- Id
- 3418
- CVE No.
- CVE-2001-0605
- Status
- Candidate
- Description
- Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data.
- Phase
- Proposed (20010727)
- Votes
- MODIFY(1) Frech | NOOP(5) Cole, Foat, Prosser, Wall, Ziese | REVIEWING(2) Bishop, Williams
- Comments
- Frech> XF:mygetright-skin-overwrite-file(6155) | In description, product should be "My GetRight" (see | http://www.mygetright.com/get.html) | Prosser> According to Discover"s Bulletin, the vendor, www.mygetright.com acknowledged the problem and fixed it in version 1.0b. However, vendor page makes no mention of this issue.