CVE-2000-0282 Information

Description

TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.

Reference

ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p20Read20me.html http://archives.neohapsis.com/archives/bugtraq/2000-04/0050.html http://www.securityfocus.com/bid/1102

Share on: