CVE-2000-0977
טרם דורגה
תיאור (מקור, אנגלית)
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.
מדדים
- EPSS — סבירות ניצול
- 9% (אחוזון 100) נכון ל-25/9/2026
מוצרים מושפעים
oatmeal_studios: mail file
קישורים
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html ExploitVendor Advisory
- http://www.securityfocus.com/bid/1807 ExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html ExploitVendor Advisory
- http://www.securityfocus.com/bid/1807 ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5358
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5358