CVE-2002-0934

critical

Description

Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.

References

http://www.securityfocus.com/bid/4983

http://www.iss.net/security_center/static/9325.php

http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html

Details

Source: Mitre, NVD

Published: 2002-10-04

Updated: 2008-09-05

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical