Security Advisory

CVE-2000-0877

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2001-09-18 04:00:00
Last updated 2024-08-08 05:37:31
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.