First published: Thu Dec 06 2001(Updated: )
Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Tarantella Enterprise | =3.0 | |
Oracle Tarantella Enterprise | =3.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0805 is classified as a medium severity vulnerability.
CVE-2001-0805 allows remote attackers to perform a directory traversal attack to read arbitrary files by using the '..' sequences in the pg parameter.
CVE-2001-0805 affects Tarantella Enterprise versions 3.0 and 3.01.
To fix CVE-2001-0805, update Tarantella Enterprise to a version that is not vulnerable.
Yes, CVE-2001-0805 can potentially expose sensitive files to unauthorized users.