CVE-1999-1377
CVSS 2.0 Score 5.0 of 10 (medium)
Details
Published Sep 9, 1999
Updated: Nov 20, 2024
Summary
CVE-1999-1377 is a vulnerability affecting Matt Wright's download.cgi version 1.0. An attacker can exploit this issue by manipulating the 'f' parameter with a '..' (dot dot) sequence, enabling unauthorized reading of arbitrary files on the affected system. This vulnerability poses a serious risk, as it enables attackers to access sensitive information and potentially gain unauthorized access to the system. It is crucial for users of the affected software to apply the available patch or upgrade to a secure version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share