Vulnerability Description
Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| My Postcards | My Postcards Platinum | 5.0 |
References
- http://packetstormsecurity.nl/0206-exploits/magiccard_vuln.txtExploit
- http://www.securiteam.com/unixfocus/5IP0G2K7FQ.htmlExploit
- http://www.securityfocus.com/bid/5029
- http://packetstormsecurity.nl/0206-exploits/magiccard_vuln.txtExploit
- http://www.securiteam.com/unixfocus/5IP0G2K7FQ.htmlExploit
- http://www.securityfocus.com/bid/5029
FAQ
What is CVE-2002-1966?
CVE-2002-1966 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
How severe is CVE-2002-1966?
CVE-2002-1966 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1966?
Check the references section above for vendor advisories and patch information. Affected products include: My Postcards My Postcards Platinum.