Korean
<< Back
VID 21732
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Brio program is vulnerable to a directory traversal vulnerability in the 'odscgi' component. Brio is a popular web application interface. Some versions of Brio is vulnerable to a directory traversal vulnerability in the 'odscgi' component. A remote attacker could exploit this vulnerability to read arbitrary files on the affected host by submitting a specially-crafted URL similar to the following:

http://[www.example.com]/ods-cgi/odscgi?HTMLFile=../../../../../../etc/passwd

* Platforms Affected:
brio.com, Brio Any version
Any operating system Any version
Recommendation No upgrade or patch available as of October 2005.

Upgrade to the latest version of Brio, when new fixed version becomes available from the Brio Web site at http://www.brio.com
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)