CVE-2011-0063 is a directory traversal vulnerability affecting Majordomo 2 versions 20110203 and earlier. It allows remote attackers to read arbitrary files by manipulating the "extra" parameter in the help command, bypassing an incomplete fix for a previous vulnerability. This flaw has a CVSS score of 5.0 (Medium), indicating it is easily exploitable over the network with low complexity and no authentication required, leading to potential information disclosure. Exploit code is publicly available, including a Metasploit module and an ExploitDB entry, suggesting a high likelihood of exploitation despite no confirmed active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20110203CPE matchmatch criteria | cpe:2.3:a:mj2:majordomo_2:*:*:*:*:*:*:*:* | ||
20110101CPE matchmatch criteria | cpe:2.3:a:mj2:majordomo_2:20110101:*:*:*:*:*:*:* | ||
20110102CPE matchmatch criteria | cpe:2.3:a:mj2:majordomo_2:20110102:*:*:*:*:*:*:* | ||
20110103CPE matchmatch criteria | cpe:2.3:a:mj2:majordomo_2:20110103:*:*:*:*:*:*:* | ||
20110104CPE matchmatch criteria | cpe:2.3:a:mj2:majordomo_2:20110104:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.