First published: Fri Dec 31 2004(Updated: )
Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenConnect | =6.4.4 | |
OpenConnect | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0465 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive data.
To fix CVE-2004-0465, update to the latest version of WebConnect that addresses this directory traversal vulnerability.
CVE-2004-0465 affects WebConnect versions 6.4.4 and 6.5, and possibly earlier versions.
CVE-2004-0465 enables remote attackers to exploit directory traversal techniques to read arbitrary INI formatted files.
Yes, CVE-2004-0465 is a vulnerability associated with OpenConnect's WebConnect software.