Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.
Advisories
Source ID Title
EUVD EUVD EUVD-2001-1111 Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T04:44:07.968Z

Reserved: 2002-03-15T00:00:00

Link: CVE-2001-1130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2001-08-02T04:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2001-1130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.