PT-2001-2339 · Unknown · Last Lines

Published

2001-12-30

·

Updated

2016-10-18

·

CVE-2001-1205

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Last Lines version 2.0
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files by utilizing '..' sequences in the error log variable.
Recommendations For Last Lines version 2.0, consider restricting access to the lastlines.cgi script until a patch is available, or avoid using the error log variable in a way that could facilitate directory traversal attacks.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2001-1205

Affected Products

Last Lines