Vulnerabilities
Vulnerable Software
Matt Wright:  >> Formhandler.cgi  Security Vulnerabilities
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
CVSS Score
5.0
EPSS Score
0.01
Published
1999-11-16
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.
CVSS Score
5.0
EPSS Score
0.048
Published
1999-11-12


Contact Us

Shodan ® - All rights reserved