7.5
CVSSv2

CVE-2001-1138

Published: 07/09/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote malicious users to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

randy parker power up html 0.8033_beta

Exploits

source: wwwsecurityfocuscom/bid/3304/info Power Up HTML is a set of HTML-like commands that can be placed into web pages It provides a central routing point to simplify programming and customization of CGI scripts A vulnerability exists in Power Up HTML which allows directory traversal through the web server using / strings in a CGI ...