PT-2006-7118 · Winamp · Winamp Web Interface
Luigi Auriemma
·
Published
2006-12-14
·
Updated
2018-10-17
·
CVE-2006-6514
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Winamp Web Interface (Wawi) versions 7.5.13 and earlier
Description
The issue allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory. This is due to an insufficient comparison used to determine whether a directory is located below the application's root directory. For example, accessing C:folder2 when the root directory is C:folder is possible.
Recommendations
For versions 7.5.13 and earlier, update to a version that addresses this issue, as the current version allows unauthorized directory access due to the insufficient comparison.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winamp Web Interface