PT-2004-2957 · Isearch · Isearch+1

CVE-2004-2061

·

Publicado

2004-07-27

·

Atualizado

2024-02-08

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RiSearch version 1.0.01 RiSearch Pro version 3.2.06
Description The issue allows remote attackers to use the show.pl script as an open proxy or read arbitrary local files by setting the url parameter to a http://, ftp://, or file:// URL.
Recommendations For RiSearch version 1.0.01, restrict access to the show.pl script to minimize the risk of exploitation. For RiSearch Pro version 3.2.06, avoid using the url parameter in the show.pl script until the issue is resolved. As a temporary workaround, consider disabling the show.pl script until a patch is available.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-2061

Produtos afetados

Isearch
Risearch Pro