CVE-2000-0977

Publication date

2001-01-22 05:00:00

Family

mitre

State

PUBLISHED

Description

mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.