CVE-2004-1678
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can…
Does this matter?
Lower severity and a low EPSS score (7.18%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.18% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- logicnow/perldesk
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109509026406554&w=2
- http://secunia.com/advisories/12512Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11160Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19712
- http://marc.info/?l=bugtraq&m=109509026406554&w=2
- http://secunia.com/advisories/12512Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11160Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19712
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.