CVE-1999-1051

Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
References
Link Resource
http://www.securityfocus.com/archive/1/34939 Exploit Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:matt_wright:formhandler.cgi:1.0:*:*:*:*:*:*:*
cpe:2.3:a:matt_wright:formhandler.cgi:2.0:*:*:*:*:*:*:*
cpe:2.3:a:matt_wright:formhandler.cgi:3.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 1999-11-16 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-1999-1051

Mitre link : CVE-1999-1051

CVE.ORG link : CVE-1999-1051


JSON object : View

Products Affected

matt_wright

  • formhandler.cgi