CVE
- Id
- 5269
- CVE No.
- CVE-2002-0879
- Status
- Candidate
- Description
- showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(2) Alderson, Frech | MODIFY(1) Jones | NOOP(4) Armstrong, Cole, Cox, Foat
- Comments
- Jones> Suggest description adds "...CFXImage 1.6.6 and earlier does not | filter form input, allowing remote attackers to read...". Regarding | abstraction, vote not to SPLIT; agree that vulnerability is lack of input | filtering. SPLITting would imply that Cross-site scripting, etc. due to | same lack of form input filtering would require a new candidate, etc.