Security Advisory

CVE-2002-0307

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2002-05-03 04:00:00
Last updated 2024-08-08 02:42:29
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's eval function.