VID |
21732 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Brio program is vulnerable to a directory traversal vulnerability in the 'odscgi' component. Brio is a popular web application interface. Some versions of Brio is vulnerable to a directory traversal vulnerability in the 'odscgi' component. A remote attacker could exploit this vulnerability to read arbitrary files on the affected host by submitting a specially-crafted URL similar to the following:
http://[www.example.com]/ods-cgi/odscgi?HTMLFile=../../../../../../etc/passwd
* Platforms Affected: brio.com, Brio Any version Any operating system Any version |
Recommendation |
No upgrade or patch available as of October 2005.
Upgrade to the latest version of Brio, when new fixed version becomes available from the Brio Web site at http://www.brio.com |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|