Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/12963 - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1011920 - Exploit | |
References | () http://sourceforge.net/project/shownotes.php?release_id=277371 - | |
References | () http://www.osvdb.org/11103 - Patch | |
References | () http://www.securityfocus.com/bid/11517 - Exploit, Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17833 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:53
NVD link : CVE-2004-2640
Mitre link : CVE-2004-2640
CVE.ORG link : CVE-2004-2640
JSON object : View
Products Affected
ryszard_pydo
- linuxstat
CWE