PT-2005-4217 · Hyper Estraier · Hyper Estraier

Published

2005-11-01

·

Updated

2008-11-11

·

CVE-2005-3421

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hyper Estraier version 1.0.1
Description The issue allows remote attackers to read unauthorized files by sending a crafted search request for a filename that contains Unicode characters. This is made possible through the estcmd in Hyper Estraier on Windows systems.
Recommendations For Hyper Estraier version 1.0.1, consider restricting access to the estcmd until a patch is available to prevent unauthorized file reading. As a temporary workaround, avoid using filenames that contain Unicode characters in search requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3421

Affected Products

Hyper Estraier