Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-2061 | First vendor Publication | 2004-07-27 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 9.8 | ||
Base Score | 9.8 | Environmental Score | 9.8 |
impact SubScore | 5.9 | Temporal Score | 9.8 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2061 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-219 | XML Routing Detour Attacks |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : RiSearch Arbitrary File Access File : nvt/risearch_arbitrary_file_access.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
8266 | RiSearch show.pl Arbitrary File Access RiSearch contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an arbitrary local file path is passed to show.pl, which will disclose the file contents resulting in a loss of confidentiality. |
8265 | RiSearch show.pl Open Proxy Relay RiSearch contains a flaw that may allow a malicious user to use the server as a proxy. The issue is triggered by the lack of validation of the url variable which is passed to show.pl. It is possible that the flaw may allow open relay access resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | RiSearch show.pl proxy attempt RuleID : 3465 - Revision : 13 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-08-04 | Name : A web application running on the remote host has an arbitrary file read vulne... File : risearch_arbitrary_file_access.nasl - Type : ACT_GATHER_INFO |
2004-08-02 | Name : The remote server may be used as an anonymous proxy. File : risearch_open_proxy.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:02 |
|
2024-11-28 12:06:28 |
|
2024-02-09 00:28:16 |
|
2021-05-04 12:02:35 |
|
2021-04-22 01:02:47 |
|
2020-05-23 00:16:07 |
|
2017-07-11 12:01:41 |
|
2016-10-18 12:01:30 |
|
2016-06-28 15:09:06 |
|
2016-04-26 13:05:36 |
|
2014-02-17 10:29:13 |
|
2014-01-19 21:22:27 |
|
2013-05-11 11:47:28 |
|