7.5
CVSSv2

CVE-2000-0810

Published: 19/12/2000 Updated: 03/05/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Auction Weaver 1.0 up to and including 1.04 does not properly validate the names of form fields, which allows remote malicious users to delete arbitrary files and directories via a .. (dot dot) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

cgi script center auction weaver 1.03

cgi script center auction weaver 1.04

cgi script center auction weaver 1.0

cgi script center auction weaver 1.01

cgi script center auction weaver 1.02