Vulnerabilities > CVE-2002-0934 - Unspecified vulnerability in JON Hedley Alienform2 1.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN jon-hedley
nessus
Summary
Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | ALIENFORM.NASL |
description | The AlienForm CGI script allows an attacker to view any file on the target computer, append arbitrary data to an existing file, and write arbitrary data to a new file. The AlienForm CGI script is installed as either af.cgi or alienform.cgi. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11027 |
published | 2002-06-11 |
reporter | This script is Copyright (C) 2002-2018 Andrew Hintz (http://guh.nu) |
source | https://www.tenable.com/plugins/nessus/11027 |
title | AlienForm2 alienform.cgi Traversal Arbitrary File Manipulation |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html
- http://www.iss.net/security_center/static/9325.php
- http://www.iss.net/security_center/static/9325.php
- http://www.securityfocus.com/bid/4983
- http://www.securityfocus.com/bid/4983