man-cgi before 1.16 allows Local File Inclusion via absolute path traversal, as demonstrated by a cgi-bin/man-cgi?/etc/passwd URI.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/148855/man-cgi-Local-File-Inclusion.html | Patch Third Party Advisory VDB Entry |
https://www.securityfocus.com/archive/1/542208/100/0/threaded | Patch Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/148855/man-cgi-Local-File-Inclusion.html | Patch Third Party Advisory VDB Entry |
https://www.securityfocus.com/archive/1/542208/100/0/threaded | Patch Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/148855/man-cgi-Local-File-Inclusion.html - Patch, Third Party Advisory, VDB Entry | |
References | () https://www.securityfocus.com/archive/1/542208/100/0/threaded - Patch, Third Party Advisory, VDB Entry |
Information
Published : 2018-08-14 18:29
Updated : 2024-11-21 03:49
NVD link : CVE-2018-14429
Mitre link : CVE-2018-14429
CVE.ORG link : CVE-2018-14429
JSON object : View
Products Affected
man-cgi_project
- man-cgi
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')