A vulnerability has been identified in Majordomo2, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "_list_file_get() [lib/Majordomo.pm] function when processing user-supplied HTTP requests or email messages, which could be exploited to conduct directory traversal attacks and disclose the contents of arbitrary files.
Vulnerable Products
Vulnerable Software: Majordomo2 versions prior to 20110204