Vulnerability Details CVE-2011-0049
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.913
EPSS Ranking 99.6%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2011-0049
-
cpe:2.3:a:mj2:majordomo_2:*
-
cpe:2.3:a:mj2:majordomo_2:20110101
-
cpe:2.3:a:mj2:majordomo_2:20110102
-
cpe:2.3:a:mj2:majordomo_2:20110103
-
cpe:2.3:a:mj2:majordomo_2:20110104
-
cpe:2.3:a:mj2:majordomo_2:20110105
-
cpe:2.3:a:mj2:majordomo_2:20110106
-
cpe:2.3:a:mj2:majordomo_2:20110107
-
cpe:2.3:a:mj2:majordomo_2:20110108
-
cpe:2.3:a:mj2:majordomo_2:20110109
-
cpe:2.3:a:mj2:majordomo_2:20110110
-
cpe:2.3:a:mj2:majordomo_2:20110111
-
cpe:2.3:a:mj2:majordomo_2:20110112
-
cpe:2.3:a:mj2:majordomo_2:20110113
-
cpe:2.3:a:mj2:majordomo_2:20110114
-
cpe:2.3:a:mj2:majordomo_2:20110115
-
cpe:2.3:a:mj2:majordomo_2:20110116
-
cpe:2.3:a:mj2:majordomo_2:20110117
-
cpe:2.3:a:mj2:majordomo_2:20110118
-
cpe:2.3:a:mj2:majordomo_2:20110119
-
cpe:2.3:a:mj2:majordomo_2:20110120
-
cpe:2.3:a:mj2:majordomo_2:20110121
-
cpe:2.3:a:mj2:majordomo_2:20110122
-
cpe:2.3:a:mj2:majordomo_2:20110123
-
cpe:2.3:a:mj2:majordomo_2:20110124
-
cpe:2.3:a:mj2:majordomo_2:20110125
-
cpe:2.3:a:mj2:majordomo_2:20110126
-
cpe:2.3:a:mj2:majordomo_2:20110127
-
cpe:2.3:a:mj2:majordomo_2:20110128
-
cpe:2.3:a:mj2:majordomo_2:20110129