← Vulnerability feed

Vulnerability record · CVE-2011-0063 · published 15 March 2011

CVE-2011-0063: Majordomo 2 help command path traversal allows arbitrary file read

Mj2 · Majordomo 2

The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier mishandles a ./.../ sequence in the "extra" parameter to the help command, causing a regular expression to produce .. (dot dot) sequences and enabling directory traversal. This is an incomplete fix for CVE-2011-0049, so the earlier patch does not fully close the flaw. It matters because a remote, unauthenticated attacker can read files outside the intended directory.

5.0 CVSS 2.0 Medium EPSS 85% · top 0.3% CWE-22 · Path traversal
5.0CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote arbitrary file read with public exploit code and a very high EPSS score, though impact is confidentiality-only.

What it is

The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier mishandles a ./.../ sequence in the "extra" parameter to the help command, causing a regular expression to produce .. (dot dot) sequences and enabling directory traversal. This is an incomplete fix for CVE-2011-0049, so the earlier patch does not fully close the flaw. It matters because a remote, unauthenticated attacker can read files outside the intended directory.

Impact

An attacker gains read access to arbitrary files on the host, limited to what the Majordomo process can read. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached remotely over the network via the help command's "extra" parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.85451 (99.7th percentile) and public references are tagged Exploit, indicating known exploit code exists. No ransomware usage is documented.

What to do

  • Upgrade Majordomo 2 past the 20110203 release or apply the vendor fix referenced in the Mozilla bugzilla entry, which is tagged Patch.
  • If patching is not immediately possible, restrict or disable the help command's "extra" parameter handling and reject inputs containing dot-dot sequences.
  • Run Majordomo under a least-privilege account so arbitrary file reads are limited to non-sensitive files.
  • Place the Majordomo service behind network controls so only trusted hosts can reach its command interface.

Detection

  • Search Majordomo logs for help command requests containing ./.../ or .. sequences in the extra parameter.
  • Monitor for anomalous file reads by the Majordomo process outside its expected directories.
  • Alert on repeated help requests with traversal-like parameters from a single source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0063 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.0CVE-2011-0049Majordomo 2 help command path traversal allows arbitrary file readMajordomo 2 before 20110131 contains a directory traversal flaw in the _list_file_get function in lib/Majordomo.pm. The help command fails to sanitiz…EPSS 95%analysed9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed6.5CVE-2026-20262Cisco Catalyst SD-WAN Manager path traversal in file uploadCisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2011-0063), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.