CVE

Id
5269  
CVE No.
CVE-2002-0879  
Status
Candidate  
Description
showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.  
Phase
Proposed (20020830)  
Votes
ACCEPT(2) Alderson, Frech | MODIFY(1) Jones | NOOP(4) Armstrong, Cole, Cox, Foat  
Comments
Jones> Suggest description adds "...CFXImage 1.6.6 and earlier does not | filter form input, allowing remote attackers to read...". Regarding | abstraction, vote not to SPLIT; agree that vulnerability is lack of input | filtering. SPLITting would imply that Cross-site scripting, etc. due to | same lack of form input filtering would require a new candidate, etc.