← Back

CVE-2011-0063

nvd nist
Published: Mar 15, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.

Affected (34)

Products: Mj2: Majordomo 2
1 product
Majordomo 2
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Mj2
Up to 20110203
Version 20110101
Version 20110102
Version 20110103
Version 20110104
Version 20110105
Version 20110106
Version 20110107
Version 20110108
Version 20110109
Version 20110110
Version 20110111
Version 20110112
Version 20110113
Version 20110114
Version 20110115
Version 20110116
Version 20110117
Version 20110118
Version 20110119
Version 20110120
Version 20110121
Version 20110122
Version 20110123
Version 20110124
Version 20110125
Version 20110126
Version 20110127
Version 20110128
Version 20110129
Version 20110130
Version 20110131
Version 20110201
Version 20110202

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.