CVE Vulnerabilities

CVE-2000-0977

Published: Dec 19, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the filename parameter in a POST request, which is then sent by email to the address specified in the email parameter.

Affected Software

NameVendorStart VersionEnd Version
Mail_fileOatmeal_studios1.10 (including)1.10 (including)

References