A security problem in Hyperseek 2000 Search Engine allows remote attackers to gain access to any world readable file on the machine (For example /etc/passwd).
Credit:
The information has been provided by MC GaN.
Problem:
Standard Perl problems are present in the statistic module. The CGI hsx.cgi does not filter ../ nor %00. By exploiting this bug, you can remotely read any file and make listing of directory. ../ - directory up, %00 hex symbol, that means end of line.