CVE

Id
4013  
CVE No.
CVE-2001-1209  
Status
Candidate  
Description
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  
Phase
Proposed (20020315)  
Votes
ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  
Comments
Christey> INCLUSION: The author of the zml.cgi program says that the vulnerable | version is not his, and that zml.cgi does not take a file parameter. | If this is an adaptation of that zml.cgi program, and the adaptation | is not generally available, then it should not be included in CVE. | Almost all of the hits on Google for "zml.cgi" are references to the | reported vulnerability, and a search for "zml" doesn"t turn up any | obvious web pages, so it cannot be determined if there is another | product that happens to use a script named zml.cgi.