CVE-2000-0810 Information

Description

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

Reference

http://www.osvdb.org/1600 http://www.securityfocus.com/bid/1782 https://exchange.xforce.ibmcloud.com/vulnerabilities/5371

Share on: