CVE

Id
4809  
CVE No.
CVE-2002-0417  
Status
Candidate  
Description
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.  
Phase
Proposed (20020611)  
Votes
ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall  
Comments