CVE

Id
5795  
CVE No.
CVE-2002-1411  
Status
Candidate  
Description
Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.  
Phase
Proposed (20030317)  
Votes
ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  
Comments
Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data.