man-cgi before 1.16 allows Local File Inclusion via absolute path traversal, as demonstrated by a cgi-bin/man-cgi?/etc/passwd URI.
References
| Link | Resource |
|---|---|
| https://www.securityfocus.com/archive/1/542208/100/0/threaded | Patch Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/148855/man-cgi-Local-File-Inclusion.html | Patch Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-08-14 11:29
Updated : 2018-10-12 08:01
NVD link : CVE-2018-14429
Mitre link : CVE-2018-14429
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
man-cgi_project
- man-cgi


