Record summary

CVE-2004-0465 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBwebconnect 6.4.4 < 6.5 - Directory Traversal / Denial of ServiceExploitDB exploitby karak0rsanNot analyzed1 file
ExploitDB

PoC details

References

7