PT-2000-1743 · Auction Weaver · Auction Weaver
Published
2000-12-19
·
Updated
2018-05-03
·
CVE-2000-0811
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Auction Weaver versions 1.0 through 1.04
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot) attack on the
username or bidfile form fields.Recommendations
For Auction Weaver versions 1.0 through 1.04, consider restricting access to the vulnerable form fields until a patch is available. As a temporary workaround, avoid using the
username and bidfile fields in sensitive operations to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Auction Weaver