Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Linuxstat | Ryszard_pydo | 0.90 (including) | 0.90 (including) |
| Linuxstat | Ryszard_pydo | 0.94 (including) | 0.94 (including) |
| Linuxstat | Ryszard_pydo | 2.0 (including) | 2.0 (including) |
| Linuxstat | Ryszard_pydo | 2.0_beta (including) | 2.0_beta (including) |
| Linuxstat | Ryszard_pydo | 2.0_beta2 (including) | 2.0_beta2 (including) |
| Linuxstat | Ryszard_pydo | 2.1 (including) | 2.1 (including) |
| Linuxstat | Ryszard_pydo | 2.2 (including) | 2.2 (including) |
| Linuxstat | Ryszard_pydo | 2.3 (including) | 2.3 (including) |