VULNERABILITY INTELLIGENCE

CVE-2000-0686

CVSS score5 MEDIUM
EPSS probability1.45%
CISA KEVNot currently listed
Published2000-10-20
Last modified2026-06-16

Description

Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.