vendor:
mcNews
by:
SecurityFocus
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: mcNews
Affected Version From: mcNews
Affected Version To: mcNews
Patch Exists: YES
Related CWE: CVE-2002-1390
CPE: cpe:a:mcnews:mcnews
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Unix, Windows
2002
mcNews Directory Traversal
mcNews does not sufficiently filter dot-dot-slash (../) sequences from URL parameters, allowing a remote attacker to disclose the contents of arbitrary web-readable files that exist on a host running the vulnerable software.
Mitigation:
Filter dot-dot-slash (../) sequences from URL parameters.