5
CVSSv2

CVE-2002-0874

Published: 05/09/2002 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote malicious users to read arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat interchange 4.8.5

redhat interchange 4.8.1

redhat interchange 4.8.2

redhat interchange 4.8.3

redhat interchange 4.8.4

Vendor Advisories

A problem has been discovered in Interchange, an e-commerce and general HTTP database display system, which can lead to an attacker being able to read any file to which the user of the Interchange daemon has sufficient permissions, when Interchange runs in "INET mode" (internet domain socket) This is not the default setting in Debian packages, but ...

Exploits

source: wwwsecurityfocuscom/bid/5453/info A vulnerability has been reported for Interchange 485 and earlier Reportedly, Interchange may disclose contents of files to attackers The vulnerability occurs due to the placement of the 'doc' folder Reportedly, the folder will be installed as follows: <INTERCHANGE_ROOT>/doc This fold ...