Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0049

89
FAUCET Score

CVE-2011-0049 is a directory traversal vulnerability in Majordomo 2 (versions prior to 20110131), specifically within the _list_file_get function in lib/Majordomo.pm. This flaw allows unauthenticated remote attackers to read arbitrary files on the server by injecting ".." sequences into the help command via crafted emails or the web interface. The vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, leading to potential information disclosure. While not listed in CISA's KEV catalog, exploit modules are publicly available in Metasploit and Nuclei, and it has a high EPSS score, suggesting a significant likelihood of exploitation. There is no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 20110130CPE matchmatch criteria
cpe:2.3:a:mj2:majordomo_2:*:*:*:*:*:*:*:*
20110101CPE matchmatch criteria
cpe:2.3:a:mj2:majordomo_2:20110101:*:*:*:*:*:*:*
20110102CPE matchmatch criteria
cpe:2.3:a:mj2:majordomo_2:20110102:*:*:*:*:*:*:*
20110103CPE matchmatch criteria
cpe:2.3:a:mj2:majordomo_2:20110103:*:*:*:*:*:*:*
20110104CPE matchmatch criteria
cpe:2.3:a:mj2:majordomo_2:20110104:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
95.39%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: Majordomo2 _list_file_get() Directory Traversal · Mar 8, 2011
Nuclei: CVE-2011-0049 · Apr 18, 2021
ExploitDB: EDB-16103 · Feb 3, 2011
This CVE's current EPSS score of 0.9539 is in the 100th percentile among its peer group of 23,690 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mozillapatch availablevia nvd_reference
View patch

References

osvdb.org / 70762
bug628064.bugzilla.mozilla.org / attachment.cgi
Patch
bugzilla.mozilla.org / show_bug.cgi
ExploitPatch
secunia.com / advisories/43125
Vendor Advisory
securityreason.com / securityalert/8061
exchange.xforce.ibmcloud.com / vulnerabilities/65113
sitewat.ch / en/Advisory/View/1
ExploitURL Repurposed
exploit-db.com / exploits/16103
kb.cert.org / vuls/id/363726
US Government Resource
securityfocus.com / archive/1/516150/100/0/threaded
securityfocus.com / bid/46127
Exploit
securitytracker.com / id
vupen.com / english/advisories/2011/0288