PT-2006-7118 · Winamp · Winamp Web Interface
Luigi Auriemma
·
Publicado
2006-12-14
·
Atualizado
2018-10-17
·
CVE-2006-6514
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Winamp Web Interface (Wawi) versions 7.5.13 and earlier
Description
The issue allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory. This is due to an insufficient comparison used to determine whether a directory is located below the application's root directory. For example, accessing C:folder2 when the root directory is C:folder is possible.
Recommendations
For versions 7.5.13 and earlier, update to a version that addresses this issue, as the current version allows unauthorized directory access due to the insufficient comparison.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Winamp Web Interface