| VID |
21732 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Brio program is vulnerable to a directory traversal vulnerability in the 'odscgi' component. Brio is a popular web application interface. Some versions of Brio is vulnerable to a directory traversal vulnerability in the 'odscgi' component. A remote attacker could exploit this vulnerability to read arbitrary files on the affected host by submitting a specially-crafted URL similar to the following:
http://[www.example.com]/ods-cgi/odscgi?HTMLFile=../../../../../../etc/passwd
* Platforms Affected: brio.com, Brio Any version Any operating system Any version |
| Recommendation |
No upgrade or patch available as of October 2005.
Upgrade to the latest version of Brio, when new fixed version becomes available from the Brio Web site at http://www.brio.com |
| Related URL |
(CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|