OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Mathopd - Directory Traversal Vulnerability

From: Mateusz Goik (mateusz.goikaliantsoft.pl)
Date: Fri Feb 03 2012 - 04:58:45 CST


Hi,

Mathopd - Security Alerts

Directory Traversal Vulnerability

Reported: 2 February 2012

Older versions of the software have a vulnerability that could lead to
directory traversal if the '*' construct for mass virtual hosting is used.

Affected: all 1.4 versions, all 1.5 versions up to 1.5p7.

Fixed in: Mathopd 1.5p7

http://www.mathopd.org/security.html
http://www.mail-archive.com/mathopd%40mathopd.org/msg00392.html