PT-2006-7118 · Winamp · Winamp Web Interface

Luigi Auriemma

·

Publicado

2006-12-14

·

Atualizado

2018-10-17

·

CVE-2006-6514

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Winamp Web Interface (Wawi) versions 7.5.13 and earlier
Description The issue allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory. This is due to an insufficient comparison used to determine whether a directory is located below the application's root directory. For example, accessing C:folder2 when the root directory is C:folder is possible.
Recommendations For versions 7.5.13 and earlier, update to a version that addresses this issue, as the current version allows unauthorized directory access due to the insufficient comparison.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6514

Produtos afetados

Winamp Web Interface