Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Auction_weaver | Cgi_script_center | * | 1.02 (including) |
References