CVE

Id
3942  
CVE No.
CVE-2001-1138  
Status
Candidate  
Description
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.  
Phase
Proposed (20020315)  
Votes
ACCEPT(2) Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese  
Comments