CVE
- Id
- 4809
- CVE No.
- CVE-2002-0417
- Status
- Candidate
- Description
- Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.
- Phase
- Proposed (20020611)
- Votes
- ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall
- Comments