CVE-2004-0578: Medium severity Qbik WinGate vulnerability
Published Jul 6, 2004
·Updated
WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-internal directory.
Affected Software
3 affected components
Qbik WinGate=6.0_beta_2
Qbik WinGate=5.0.5
Qbik WinGate=5.2.3
Event History
Jul 6, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0578?
CVE-2004-0578 is classified as a high severity vulnerability that allows unauthorized file access.
2
How do I fix CVE-2004-0578?
To fix CVE-2004-0578, upgrade to a patched version of WinGate that addresses this vulnerability.
3
Which versions of WinGate are affected by CVE-2004-0578?
CVE-2004-0578 affects WinGate versions 5.0.5, 5.2.3, and 6.0 beta 2.
4
What kind of attack is enabled by CVE-2004-0578?
CVE-2004-0578 allows remote attackers to read arbitrary files on the server via specially crafted URL requests.
5
Is there a workaround for CVE-2004-0578?
A potential workaround for CVE-2004-0578 is to restrict access to the wingate-internal directory until the software is updated.