Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Auction_weaver |
Cgi_script_center |
* |
1.02 (including) |
References