← לוח פגיעויות

CVE-2000-0810

טרם דורגה

טרם דורג — בהתאם למדיניות NVD מאפריל 2026, רוב ה-CVE אינם מנותחים מיידית. ציון EPSS (אם קיים) עדיין מוצג.

תיאור (מקור, אנגלית)

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

מדדים

מוצרים מושפעים

cgi_script_center: auction weaver

קישורים