Korean
<< Back
VID 21168
Severity 30
Port 80, ¡¦
Protocol TCP
Class CGI
Detailed Description The "anacondaclip.pl" CGI is installed. Anaconda Clipper is a headline-gathering tool.
The anacondaclip.pl script of Anaconda Clipper 3.3 could allow a remote attacker to traverse directories on the Web server, due to insufficient checks performed on parameters passed to anacondaclip.pl through the "template" argument. A remote attacker can send an HTTP GET request with "dot dot" sequences (/../) to traverse directories and gain read access to sensitive files on the Web server with the privileges of the http daemon (usually root or nobody).
Recommendation No remedy available as of June 2014. Remote the CGI
Related URL CVE-2001-0593 (CVE)
Related URL 2512 (SecurityFocus)
Related URL 6286 (ISS)