RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-07-27 04:00
Updated : 2017-07-11 01:31
NVD link : CVE-2004-2061
Mitre link : CVE-2004-2061
JSON object : View
Products Affected
risearch_software
- risearch
- risearch_pro
CWE
