20020227 Remote exploit against xtelld and other funmailing list
http://marc.info/?l=bugtraq&m=101494896516467&w=2 CVE-2002-0333
xtell 2.6.1 - User Status Remote Information Disclosure
Record summary
CVE-2002-0333 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBxtell 2.6.1 - User Status Remote Information DisclosureExploitDB exploitby spybreakNot analyzed1 file
References
5DSA-121Vendor advisory
http://www.debian.org/security/2002/dsa-121 xtell-tty-directory-traversal(8313)vdb entry
http://www.iss.net/security_center/static/8313.php 4194vdb entry
http://www.securityfocus.com/bid/4194 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0333