PT-2004-1585 · Unknown · Webconnect

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-0465

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WebConnect versions 6.4.4 through 6.5
Description A directory traversal issue exists, allowing remote attackers to read keys within arbitrary INI formatted files. This is achieved by using "..//" sequences in the WCP USER parameter.
Recommendations For versions 6.4.4 through 6.5, restrict access to the WCP USER parameter to minimize the risk of exploitation. Avoid using the WCP USER parameter with "..//" sequences in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0465

Affected Products

Webconnect