VULNERABILITY INTELLIGENCE
CVE-2000-0686
CVSS score5 MEDIUM
EPSS probability1.45%
CISA KEVNot currently listed
Published2000-10-20
Last modified2026-06-16
Description
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.