CVE
- Id
- 5795
- CVE No.
- CVE-2002-1411
- Status
- Candidate
- Description
- Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.
- Phase
- Proposed (20030317)
- Votes
- ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall
- Comments
- Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data.