Back to Database
Status published
High
CVE-2000-0810
Auction Weaver 1.0 through 1.04 does not properly validate the...
Vulnerability Description
Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2000-0810
Credits & Attribution
No credits recorded in the NVD database.
References
More from cgi script center
View All →CVE-2001-0086
CGI Script Center Subscribe Me LITE 2.0 and earlier allows...
Medium
5
CVE-2000-0811
Auction Weaver 1.0 through 1.04 allows remote attackers to read...
Medium
5
CVE-2000-0690
Auction Weaver CGI script 1.02 and earlier allows remote attackers...
Critical
10
CVE-2000-0689
Account Manager LITE does not properly authenticate attempts to change...
High
7.5
CVE-2000-0688
Subscribe Me LITE does not properly authenticate attempts to change...
High
7.5
Affected Vendor
cgi script center
View all reports →Affected Software
auction weaver
Vulnerable Versions:
1.0, 1.01, 1.02, 1.03, 1.04
Timeline
Official Publish:
January 22nd, 2001
Last Modified:
August 8th, 2024
Added to House:
July 17th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.