Security Advisory

CVE-2004-0303

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2004-03-18 05:00:00
Last updated 2024-08-08 00:17:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.