PT-2004-1457 · Owls · Owls

Publicado

2004-03-18

·

Atualizado

2017-07-11

·

CVE-2004-0303

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OWLS version 1.0
Description The issue allows remote attackers to retrieve arbitrary files. This can be achieved by providing absolute pathnames in certain parameters, specifically the file parameter in "/glossaries/index.php", the filename parameter in "/readings/index.php", or the filename parameter in "/multiplechoice/resultsignore.php". For example, an attacker could attempt to access sensitive system files like "/etc/passwd".
Recommendations For OWLS version 1.0, as a temporary workaround, consider restricting access to the affected API endpoints "/glossaries/index.php", "/readings/index.php", and "/multiplechoice/resultsignore.php" to minimize the risk of exploitation. Avoid using the file and filename parameters in these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0303

Produtos afetados

Owls