760
VMScore

CVE-2004-2061

Published: 27/07/2004 Updated: 08/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote malicious users to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) , (2) ftp://, or (3) file:// URL.

Vulnerable Product Search on Vulmon Subscribe to Product

risearch risearch 1.0.01

risearch risearch pro 3.2.6

Exploits

source: wwwsecurityfocuscom/bid/10812/info RiSearch and RiSearch Pro are reported prone to an open proxy vulnerability It is reported that the issue presents itself due to a lack of sufficient sanitization performed on user supplied URI parameters A remote attacker may exploit this condition in order to launch attacks against local a ...
source: wwwsecurityfocuscom/bid/10812/info RiSearch and RiSearch Pro are reported prone to an open proxy vulnerability It is reported that the issue presents itself due to a lack of sufficient sanitization performed on user supplied URI parameters A remote attacker may exploit this condition in order to launch attacks against local and ...

Github Repositories

Go package of CWE IDs and metadata

cwe Go package of CWE IDs and metadata The list is generated from a CSV from the Comprehensive CWE Dictionary Example Here's CWE-918: "CWE-918": { Name: "Server-Side Request Forgery (SSRF)", WeaknessAbstraction: "Base", Status: "Incomplete", Description: "The web server receives