Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-2493

Overview

Vulnerability Score 4.0 4.0
CVE Id CVE-2004-2493
Last Modified 05 Sep 2008 04:44:17
Published 31 Dec 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2004-2493

Summary

Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.

Vulnerable Systems

Application

  • Hitachi Groupmax World Wide Web 02 00

  • Hitachi Groupmax World Wide Web 02 20

  • Hitachi Groupmax World Wide Web 02 20 A

  • Hitachi Groupmax World Wide Web 02 31 I

  • Hitachi Groupmax World Wide Web 03 00

  • Hitachi Groupmax World Wide Web 03 10 H

  • Hitachi Groupmax World Wide Web 03 11 B

  • Hitachi Groupmax World Wide Web 2

  • Hitachi Groupmax World Wide Web 3

  • Hitachi Groupmax World Wide Web Desktop 05 00

  • Hitachi Groupmax World Wide Web Desktop 05 11 F

  • Hitachi Groupmax World Wide Web Desktop 05 11 I

  • Hitachi Groupmax World Wide Web Desktop 05 11 J

  • Hitachi Groupmax World Wide Web Desktop 06 00

  • Hitachi Groupmax World Wide Web Desktop 06 50 B

  • Hitachi Groupmax World Wide Web Desktop 06 50 C

  • Hitachi Groupmax World Wide Web Desktop 06 51

  • Hitachi Groupmax World Wide Web Desktop 06 51 B

  • Hitachi Groupmax World Wide Web Desktop 06 51 C

  • Hitachi Groupmax World Wide Web Desktop 06 52

  • Hitachi Groupmax World Wide Web Desktop 06 52 B

  • Hitachi Groupmax World Wide Web Desktop 5

  • Hitachi Groupmax World Wide Web Desktop 6

  • Hitachi Groupmax World Wide Web Desktop Gold


References

CONFIRM - http://www.hitachi-support.com/security_e/vuls_e/HS04-007_e/01-e.html

XF - groupmax-directory-traversal(18278)

BID - 11773

OSVDB - 12153

SECUNIA - 13321


Last Updated: 27 May 2016 10:39:30