Back

CVE-2005-0202

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
gnu mailman 2.1
gnu mailman 2.1.1
gnu mailman 2.1.2
gnu mailman 2.1.3
gnu mailman 2.1.4
gnu mailman 2.1.5
gnu mailman 2.1b1

GitHub Security Advisory GHSA-87jx-4wq7-9wr5

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.86%

Top 14% most likely to be exploited

Threat Score 20.9 / 100

Data Sources

NVD EPSS GitHub