CVE-2004-0696: Medium severity 4d WebStar vulnerability
Published Jul 16, 2004
·Updated
The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "" (asterisk) character.
Affected Software
9 affected components
4d WebStar=4.0
4d WebStar=5.2
4d WebStar=5.2.1
4d WebStar=5.2.2
4d WebStar=5.2.3
4d WebStar=5.2.4
4d WebStar=5.3
4d WebStar=5.3.1
4d WebStar=5.3.2
Event History
Jul 16, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0696?
CVE-2004-0696 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2004-0696?
To fix CVE-2004-0696, upgrade to a version of 4D WebSTAR that is not susceptible to this vulnerability.
3
What does CVE-2004-0696 allow attackers to do?
CVE-2004-0696 allows remote attackers to list arbitrary directories via a specially crafted URL.
4
Which versions of 4D WebSTAR are affected by CVE-2004-0696?
CVE-2004-0696 affects versions 5.3.2 and earlier of 4D WebSTAR.
5
Is CVE-2004-0696 a local or remote vulnerability?
CVE-2004-0696 is a remote vulnerability that can be exploited without physical access to the server.