CVE Vulnerabilities

CVE-2004-0465

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via ..// sequences in the WCP_USER parameter.

Affected Software

NameVendorStart VersionEnd Version
WebconnectOpenconnect6.4.4 (including)6.4.4 (including)
WebconnectOpenconnect6.5 (including)6.5 (including)

References