20050314 LimeWire Gnutella client two vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=111082448213238&w=2 CVE-2005-0788
LimeWire 4.1.2 < 4.5.6 - 'GET' Remote File Read
Record summary
CVE-2005-0788 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLimeWire 4.1.2 < 4.5.6 - 'GET' Remote File ReadExploitDB exploitby lammatNot analyzed1 file
References
514555Third-party advisory
http://secunia.com/advisories/14555 GLSA-200503-37Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml limewire-client-information-disclosure(19693)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19693 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0788