CVE Feed

    Dashboard / CVE / CVE-2011-0063

    CVE-2011-0063

    The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.

    Published:Mar 15, 2011
    Last Modified:Apr 11, 2025
    EPS:Mar 15, 2011
    EPSS Score:0.89981
    CVSS Score:5

    Affected Products

    Vendor
    Mj2
    Product
    Majordomo 2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High