CVE Vulnerabilities

CVE-2000-0810

Published: Dec 19, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

Affected Software

NameVendorStart VersionEnd Version
Auction_weaverCgi_script_center1.0 (including)1.0 (including)
Auction_weaverCgi_script_center1.01 (including)1.01 (including)
Auction_weaverCgi_script_center1.02 (including)1.02 (including)
Auction_weaverCgi_script_center1.03 (including)1.03 (including)
Auction_weaverCgi_script_center1.04 (including)1.04 (including)

References