PT-2006-7118 · Winamp · Winamp Web Interface

Luigi Auriemma

·

Published

2006-12-14

·

Updated

2018-10-17

·

CVE-2006-6514

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Winamp Web Interface (Wawi) versions 7.5.13 and earlier
Description The issue allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory. This is due to an insufficient comparison used to determine whether a directory is located below the application's root directory. For example, accessing C:folder2 when the root directory is C:folder is possible.
Recommendations For versions 7.5.13 and earlier, update to a version that addresses this issue, as the current version allows unauthorized directory access due to the insufficient comparison.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6514

Affected Products

Winamp Web Interface