PT-2001-1979 · Unknown · Interactive Story

Published

2001-12-06

·

Updated

2017-10-10

·

CVE-2001-0804

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Interactive Story version 1.3
Description A directory traversal issue exists, allowing a remote attacker to read arbitrary files. This is achieved through a .. (dot dot) attack on the next parameter in the story.pl file.
Recommendations For Interactive Story version 1.3, consider restricting access to the story.pl file or the next parameter to minimize the risk of exploitation. Avoid using the next parameter in a way that could facilitate a directory traversal attack until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0804

Affected Products

Interactive Story