Vulnerability record · CVE-2011-0063 · published 15 March 2011
CVE-2011-0063: Majordomo 2 help command path traversal allows arbitrary file read
Mj2 · Majordomo 2
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier mishandles a ./.../ sequence in the "extra" parameter to the help command, causing a regular expression to produce .. (dot dot) sequences and enabling directory traversal. This is an incomplete fix for CVE-2011-0049, so the earlier patch does not fully close the flaw. It matters because a remote, unauthenticated attacker can read files outside the intended directory.
Description
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read with public exploit code and a very high EPSS score, though impact is confidentiality-only.
What it is
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier mishandles a ./.../ sequence in the "extra" parameter to the help command, causing a regular expression to produce .. (dot dot) sequences and enabling directory traversal. This is an incomplete fix for CVE-2011-0049, so the earlier patch does not fully close the flaw. It matters because a remote, unauthenticated attacker can read files outside the intended directory.
Impact
An attacker gains read access to arbitrary files on the host, limited to what the Majordomo process can read. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached remotely over the network via the help command's "extra" parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.85451 (99.7th percentile) and public references are tagged Exploit, indicating known exploit code exists. No ransomware usage is documented.
What to do
- Upgrade Majordomo 2 past the 20110203 release or apply the vendor fix referenced in the Mozilla bugzilla entry, which is tagged Patch.
- If patching is not immediately possible, restrict or disable the help command's "extra" parameter handling and reject inputs containing dot-dot sequences.
- Run Majordomo under a least-privilege account so arbitrary file reads are limited to non-sensitive files.
- Place the Majordomo service behind network controls so only trusted hosts can reach its command interface.
Detection
- Search Majordomo logs for help command requests containing ./.../ or .. sequences in the extra parameter.
- Monitor for anomalous file reads by the Majordomo process outside its expected directories.
- Alert on repeated help requests with traversal-like parameters from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0063 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0063), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.