RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=109095196526490&w=2 | Mailing List |
http://secunia.com/advisories/12173 | Broken Link Vendor Advisory |
http://securitytracker.com/id?1010788 | Broken Link Third Party Advisory VDB Entry |
http://www.osvdb.org/8265 | Broken Link |
http://www.osvdb.org/8266 | Broken Link |
http://www.securityfocus.com/bid/10812 | Broken Link Exploit Third Party Advisory VDB Entry Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16817 | Third Party Advisory VDB Entry |
http://marc.info/?l=bugtraq&m=109095196526490&w=2 | Mailing List |
http://secunia.com/advisories/12173 | Broken Link Vendor Advisory |
http://securitytracker.com/id?1010788 | Broken Link Third Party Advisory VDB Entry |
http://www.osvdb.org/8265 | Broken Link |
http://www.osvdb.org/8266 | Broken Link |
http://www.securityfocus.com/bid/10812 | Broken Link Exploit Third Party Advisory VDB Entry Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16817 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-07-27 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-2061
Mitre link : CVE-2004-2061
CVE.ORG link : CVE-2004-2061
JSON object : View
Products Affected
risearch
- risearch_pro
- risearch
CWE
CWE-918
Server-Side Request Forgery (SSRF)