CVE-2001-1138 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.
Reference
http://www.securityfocus.com/archive/1/212679 http://www.securityfocus.com/bid/3304 https://exchange.xforce.ibmcloud.com/vulnerabilities/7092
Share on: