Directory traversal vulnerability in Avi Alkalay contribute.cgi (aka contribute.pl), dated 16 Jun 2002, allows remote attackers to overwrite arbitrary files via ".." sequences in the contribdir variable.
Link | Tags |
---|---|
http://www.cirt.net/advisories/alkalay.shtml | vendor advisory |
http://www.osvdb.org/19522 | vdb entry exploit |