VulnerabilityModified
CVE-2004-2061
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
CRITICAL 9.8EPSS 5.70%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.70% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- risearch/risearch · risearch/risearch pro
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109095196526490&w=2Mailing List
- http://secunia.com/advisories/12173Broken Link, Vendor Advisory
- http://securitytracker.com/id?1010788Broken Link, Third Party Advisory, VDB Entry
- http://www.osvdb.org/8265Broken Link
- http://www.osvdb.org/8266Broken Link
- http://www.securityfocus.com/bid/10812Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16817Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=109095196526490&w=2Mailing List
- http://secunia.com/advisories/12173Broken Link, Vendor Advisory
- http://securitytracker.com/id?1010788Broken Link, Third Party Advisory, VDB Entry
- http://www.osvdb.org/8265Broken Link
- http://www.osvdb.org/8266Broken Link
- http://www.securityfocus.com/bid/10812Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16817Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.