PT-2001-1979 · Unknown · Interactive Story
Published
2001-12-06
·
Updated
2017-10-10
·
CVE-2001-0804
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Interactive Story version 1.3
Description
A directory traversal issue exists, allowing a remote attacker to read arbitrary files. This is achieved through a .. (dot dot) attack on the
next parameter in the story.pl file.Recommendations
For Interactive Story version 1.3, consider restricting access to the story.pl file or the
next parameter to minimize the risk of exploitation. Avoid using the next parameter in a way that could facilitate a directory traversal attack until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Interactive Story