VulnerabilityModified
CVE-2005-3097
Directory traversal vulnerability in Avi Alkalay contribute.cgi (aka contribute.pl), dated 16 Jun 2002, allows remote attackers to overwrite arbitrary files via ".." sequences in the contribdir variable.
MEDIUM 5.0EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Avi Alkalay contribute.cgi (aka contribute.pl), dated 16 Jun 2002, allows remote attackers to overwrite arbitrary files via ".." sequences in the contribdir variable.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- avi alkalay/contribute.cgi
- Source
- cve@mitre.org
References
- http://www.cirt.net/advisories/alkalay.shtmlVendor Advisory
- http://www.osvdb.org/19522Exploit
- http://www.cirt.net/advisories/alkalay.shtmlVendor Advisory
- http://www.osvdb.org/19522Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.