Back

CVE-2002-1966

Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
my_postcards my_postcards_platinum 5.0
my_postcards my_postcards_platinum 6.0

GitHub Security Advisory GHSA-m2cx-94gr-5629

Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 3.13%

Top 13% most likely to be exploited

Threat Score 20.9 / 100

Data Sources

NVD EPSS GitHub