First published: Fri Dec 31 2004(Updated: )
Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Groupmax World Wide Web Desktop | =5 | |
Hitachi Groupmax World Wide Web | =03_00 | |
Hitachi Groupmax World Wide Web | =02_00 | |
Hitachi Groupmax World Wide Web Desktop | =06_52 | |
Hitachi Groupmax World Wide Web Desktop | =06_51_c | |
Hitachi Groupmax World Wide Web Desktop | =06_50_c | |
Hitachi Groupmax World Wide Web | =03_10_h | |
Hitachi Groupmax World Wide Web Desktop | =gold | |
Hitachi Groupmax World Wide Web Desktop | =05_00 | |
Hitachi Groupmax World Wide Web | =02_20_a | |
Hitachi Groupmax World Wide Web Desktop | =05_11_j | |
Hitachi Groupmax World Wide Web Desktop | =06_00 | |
Hitachi Groupmax World Wide Web Desktop | =06_50_b | |
Hitachi Groupmax World Wide Web Desktop | =06_51 | |
Hitachi Groupmax World Wide Web Desktop | =06_51 | |
Hitachi Groupmax World Wide Web | =2 | |
Hitachi Groupmax World Wide Web | =02_20 | |
Hitachi Groupmax World Wide Web Desktop | =6 | |
Hitachi Groupmax World Wide Web | =3 | |
Hitachi Groupmax World Wide Web Desktop | =05_11_f | |
Hitachi Groupmax World Wide Web Desktop | =06_51_b | |
Hitachi Groupmax World Wide Web Desktop | =05_11_i | |
Hitachi Groupmax World Wide Web | =02_31_i | |
Hitachi Groupmax World Wide Web Desktop | =06_52 | |
Hitachi Groupmax World Wide Web Desktop | =06_52_b | |
Hitachi Groupmax World Wide Web | =03_11_b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2493 is classified as a moderate severity vulnerability.
To fix CVE-2004-2493, update to the latest version of Hitachi Groupmax or apply available security patches.
CVE-2004-2493 affects authenticated users of Hitachi Groupmax World Wide Web versions 2, 3, and Desktop versions 5 and 6.
CVE-2004-2493 is a directory traversal vulnerability allowing unauthorized file access.
Yes, CVE-2004-2493 can be exploited remotely by authenticated users to read arbitrary .html files.