S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2011-0049 Scanner

CVE-2011-0049 scanner - Directory Traversal vulnerability in Majordomo 2

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2011-0049
5.0
CVSS

Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Majordomo 2 is a software widely used for managing electronic mailing lists. With Majordomo 2, a user can create, configure and administer email lists, allowing users to send messages to each other without having to send individual emails. This software is typically used in organizations that require communication among members, such as companies, academic institutions, and communities.

The CVE-2011-0049 vulnerability is a directory traversal flaw in the Majordomo 2 software. It occurs in the _list_file_get function in lib/Majordomo.pm. This vulnerability allows a remote attacker to gain access to files that they should not have access to, by using ".." sequences in the help command. This vulnerability can be exploited through a crafted email or through the web interface, more specifically through the cgi-bin/mj_wwwusr.

This vulnerability can lead to serious consequences if it is exploited. It could allow an attacker to read sensitive information stored on the system, such as passwords, confidential emails, and other personal information. Furthermore, an attacker could use the information obtained through this vulnerability to carry out more complex attacks, such as social engineering or spear-phishing.

Thanks to the advanced features of the s4e.io platform, those interested in learning about vulnerabilities in their digital assets can do so easily and quickly. The platform offers a comprehensive suite of tools, such as vulnerability scanning, penetration testing, and network monitoring, to help companies and individuals identify and fix security flaws in their systems. By using this platform, users can stay ahead of potential attackers and protect their digital assets effectively.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update the Majordomo 2 software to the latest version to ensure that the vulnerability has been patched.
  • Add restrictions to the web interface to prevent unauthorized access.
  • Configure the system to reject email commands containing ".." sequences in the help command.
  • Monitor logs and system activity to detect any suspicious activity.
  • Use an intrusion detection system (IDS) to detect and prevent attacks against the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2011-0049 scanner - Directory Traversal vulnerability in Majordomo 2 | S4E