CVE-2004-0273: Path Traversal
Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0273?
CVE-2004-0273 is considered to be of moderate severity due to its ability to allow remote file uploads.
How do I fix CVE-2004-0273?
To mitigate CVE-2004-0273, users should upgrade to the latest version of RealOne Player or RealOne Enterprise Desktop that addresses this vulnerability.
Which software is affected by CVE-2004-0273?
CVE-2004-0273 affects RealOne Player 1.0, 2.0, and various versions of RealOne Enterprise Desktop.
What type of attack does CVE-2004-0273 facilitate?
CVE-2004-0273 facilitates directory traversal attacks that allow attackers to upload arbitrary files.
Is there any workaround for CVE-2004-0273?
As a workaround for CVE-2004-0273, users should avoid opening .rjs skin files from untrusted sources.