PT-2004-3065 · Caravan · Caravan

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2170

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Caravan versions 2.00/03d and earlier
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved via the fname parameter in the sample showcode.html file.
Recommendations For Caravan versions 2.00/03d and earlier, avoid using the fname parameter in the sample showcode.html file until a fix is available. As a temporary workaround, consider restricting access to the sample showcode.html file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2170

Affected Products

Caravan