Back to search
CVE-2001-1118
Published: Jun 25, 2002
Modified: Aug 8, 2024
PUBLISHED
Description
A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
3145
vdb-entry
x_refsource_BID
roxen-urlrectifier-retrieve-files(6937)
vdb-entry
x_refsource_XF
http://download.roxen.com/2.0/patch/security-notice.html
x_refsource_CONFIRM
20010802 FW: Security alert: Remote user can access any file
mailing-list
x_refsource_BUGTRAQ
20010802 Roxen security alert: URL decoding vulnerable
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now