CVE-2004-2640 Information

Description

Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

Reference

http://secunia.com/advisories/12963 http://securitytracker.com/id?1011920 http://sourceforge.net/project/shownotes.php?release_id=277371 http://www.osvdb.org/11103 http://www.securityfocus.com/bid/11517 https://exchange.xforce.ibmcloud.com/vulnerabilities/17833

Share on: