PT-2004-2646 · Webapp · Webapp

Jérôme Athias

·

Published

2004-08-24

·

Updated

2017-07-11

·

CVE-2004-1742

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WebAPP version 0.9.9
Description A directory traversal issue allows remote attackers to view arbitrary files by using a .. (dot dot) in the viewcat parameter.
Recommendations For WebAPP version 0.9.9, restrict access to the viewcat parameter to minimize the risk of exploitation. Avoid using the viewcat parameter with untrusted input until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1742

Affected Products

Webapp