Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/34939 | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 1999-11-15 21:00
Updated : 2008-09-05 13:18
NVD link : CVE-1999-1051
Mitre link : CVE-1999-1051
JSON object : View
CWE
Products Affected
matt_wright
- formhandler.cgi