5
CVSSv2

CVE-2001-0217

Published: 02/06/2001 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in PALS Library System pals-cgi program allows remote malicious users to read arbitrary files via a .. (dot dot) in the documentName parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mnscu pals webpals 1.0

Exploits

source: wwwsecurityfocuscom/bid/2372/info A specially crafted URL composed of a known filename, will disclose the requested file residing on a machine running WebPALS This vulnerability will also allow an attacker to execute arbitrary code with root privileges target/cgi-bin/pals-cgi?palsAction=restart&documentName=url_to_ ...