vendor:
Multi-Communication Package
by:
Unknown
9
CVSS
CRITICAL
Arbitrary File Disclosure and Command Execution
22
CWE
Product Name: Multi-Communication Package
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2000-0273
CPE: a:technote:multi-communication_package
Platforms Tested:
2000
Technote Inc. Multi-Communication Package Arbitrary File Disclosure and Command Execution Vulnerability
The 'main.cgi' script in Technote Inc. Multi-Communication Package allows remote attackers to read arbitrary files and execute arbitrary commands via a ../ (dot dot slash) in the filename parameter.
Mitigation:
Upgrade to a newer version of Technote Inc. Multi-Communication Package that is not vulnerable to this issue.