PT-2001-1959 · Cosmicperl · Cosmicperl Directory Pro
Published
2001-10-12
·
Updated
2016-05-25
·
CVE-2001-0780
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cosmicperl Directory Pro version 2.0
Description
The issue allows remote attackers to gain sensitive information. This is achieved by exploiting a directory traversal vulnerability in the cosmicpro.cgi component. Specifically, the vulnerability can be triggered by including a .. (dot dot) in the
SHOW parameter of a request.Recommendations
For Cosmicperl Directory Pro version 2.0, consider restricting access to the cosmicpro.cgi component until a patch is available. As a temporary workaround, avoid using the
SHOW parameter in requests to the cosmicpro.cgi component.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cosmicperl Directory Pro