Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0049 PoC — Majordomo 2 _list_file_get函数目录遍历漏洞

Source
Associated Vulnerability
Title:Majordomo 2 _list_file_get函数目录遍历漏洞 (CVE-2011-0049)
Description:Majordomo是一个流行的用Perl实现的(majordomo.pl)处理邮件列表的软件。 Majordomo 2 20110131之前版本中的ib/Majordomo.pm中的_list_file_get函数中存在目录遍历漏洞。远程攻击者可以借助在帮助命令中的".."序列,读取任意文件。
Description
A directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.
File Snapshot

id: CVE-2011-0049 info: name: Majordomo2 - SMTP/HTTP Directory Traversal author: pikpikcu sev ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.