CVE-2002-0417

Publication date

2002-06-11 04:00:00

Family

mitre

State

PUBLISHED

Description

Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.