CVE-2001-1130
N/A
N/A
Summary
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7003
- http://www.securityfocus.com/archive/1/201216
- http://www.novell.com/linux/security/advisories/2001_027_sdb_txt.html
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7003
- http://www.securityfocus.com/archive/1/201216
- http://www.novell.com/linux/security/advisories/2001_027_sdb_txt.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.