Vulnerabilities > CVE-2002-2033 - Unspecified vulnerability in Faqmanager Faqmanager.Cgi

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
faqmanager
nessus

Summary

faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00).

Nessus

NASL familyCGI abuses
NASL idFAQMANAGER.NASL
descriptionFAQManager is a Perl-based CGI for maintaining a list of Frequently Asked Questions. Using a specially crafted URL, a remote attacker can use this CGI to view arbitrary files on the web server. For example: http://www.example.com/cgi-bin/faqmanager.cgi?toc=/etc/passwd%00
last seen2020-06-01
modified2020-06-02
plugin id10837
published2002-01-25
reporterThis script is Copyright (C) 2002-2018 Matt Moore
sourcehttps://www.tenable.com/plugins/nessus/10837
titleFAQManager 'faqmanager.cgi' 'toc' Parameter Arbitrary File Access