CVE
- Id
- 3587
- CVE No.
- CVE-2001-0780
- Status
- Candidate
- Description
- Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.
- Phase
- Proposed (20011012)
- Votes
- MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall
- Comments
- Frech> XF:directory-pro-directory-traversal(6632) | All references point to CGI with the name of | directorypro.cgi, not cosmicpro.cgi as listed in description. | Christey> Not sure how cosmicpro.cgi got in there. It should be | directorypro.cgi as indicated by Andre.