5
CVSSv2

CVE-2004-1678

Published: 13/09/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote malicious users to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.

Vulnerable Product Search on Vulmon Subscribe to Product

logicnow perldesk

Exploits

source: wwwsecurityfocuscom/bid/11160/info It is reported that PerlDesk is susceptible to a server-side script execution vulnerability This vulnerability may be exploited to execute the contents of Perl scripts contained on the affected server filesystem This will execute script code in the context of the affected CGI application, typi ...