CVE-1999-1050

Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:matt_wright:formhandler.cgi:1.0:*:*:*:*:*:*:*
cpe:2.3:a:matt_wright:formhandler.cgi:2.0:*:*:*:*:*:*:*
cpe:2.3:a:matt_wright:formhandler.cgi:3.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:30

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/34600 - () http://www.securityfocus.com/archive/1/34600 -
References () http://www.securityfocus.com/archive/1/34939 - Exploit, Vendor Advisory () http://www.securityfocus.com/archive/1/34939 - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/798 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/798 - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/799 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/799 - Exploit, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/3550 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/3550 -

Information

Published : 1999-11-12 05:00

Updated : 2024-11-20 23:30


NVD link : CVE-1999-1050

Mitre link : CVE-1999-1050

CVE.ORG link : CVE-1999-1050


JSON object : View

Products Affected

matt_wright

  • formhandler.cgi