Vulnerabilities > CVE-2000-0811 - Unspecified vulnerability in CGI Script Center Auction Weaver

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cgi-script-center

Summary

Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/23375/auction.weaver.txt
idPACKETSTORM:23375
last seen2016-12-05
published2000-10-19
reportermitre.org
sourcehttps://packetstormsecurity.com/files/23375/auction.weaver.txt.html
titleauction.weaver.txt