5
CVSSv2

CVE-2001-1209

Published: 31/12/2001 Updated: 30/04/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in zml.cgi allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

abe timmerman zml.cgi 0.0

Exploits

source: wwwsecurityfocuscom/bid/3759/info zmlcgi is a perl script which can be used to support server side include directives under Apache It recognizes a simple set of commands, and allows access to cgi parameters and environment variables It can run on Linux and Unix systems or any other platform with Apache and Perl support zmlcg ...