Unknown
CVE-2011-0063
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./…/ sequence in the “extra” parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- majordomo 2,
- majordomo 2 20110101,
- majordomo 2 20110102,
- majordomo 2 20110103,
- majordomo 2 20110104,
- majordomo 2 20110105,
- majordomo 2 20110106,
- majordomo 2 20110107,
- majordomo 2 20110108,
- majordomo 2 20110109,
- majordomo 2 20110110,
- majordomo 2 20110111,
- majordomo 2 20110112,
- majordomo 2 20110113,
- majordomo 2 20110114,
- majordomo 2 20110115,
- majordomo 2 20110116,
- majordomo 2 20110117,
- majordomo 2 20110118,
- majordomo 2 20110119,
- majordomo 2 20110120,
- majordomo 2 20110121,
- majordomo 2 20110122,
- majordomo 2 20110123,
- majordomo 2 20110124,
- majordomo 2 20110125,
- majordomo 2 20110126,
- majordomo 2 20110127,
- majordomo 2 20110128,
- majordomo 2 20110129,
- majordomo 2 20110130,
- majordomo 2 20110131,
- majordomo 2 20110201,
- majordomo 2 20110202
References
Advisory
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: