Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.
References
| Link | Resource |
|---|---|
| http://sourceforge.net/project/shownotes.php?release_id=277371 | |
| http://www.securityfocus.com/bid/11517 | Exploit Patch |
| http://www.osvdb.org/11103 | Patch |
| http://securitytracker.com/id?1011920 | Exploit |
| http://secunia.com/advisories/12963 | Patch Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17833 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-12-31 05:00
Updated : 2017-07-20 01:29
NVD link : CVE-2004-2640
Mitre link : CVE-2004-2640
JSON object : View
Products Affected
ryszard_pydo
- linuxstat
CWE
