Vulnerabilities > CVE-2004-0303 - Remote File Disclosure vulnerability in Owl's Workshop

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
fools-workshop
exploit available

Summary

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

Vulnerable Configurations

Part Description Count
Application
Fools_Workshop
1

Exploit-Db

  • descriptionFool's Workshop Owl's Workshop 1.0 readings/index.php Arbitrary File Access. CVE-2004-0303. Webapps exploit for php platform
    idEDB-ID:23726
    last seen2016-02-02
    modified2004-02-18
    published2004-02-18
    reporterG00db0y
    sourcehttps://www.exploit-db.com/download/23726/
    titleFool's Workshop Owl's Workshop 1.0 readings/index.php Arbitrary File Access
  • descriptionFool's Workshop Owl's Workshop 1.0 glossaries/index.php file Parameter Arbitrary File Access. CVE-2004-0303. Webapps exploit for php platform
    idEDB-ID:23725
    last seen2016-02-02
    modified2004-02-18
    published2004-02-18
    reporterG00db0y
    sourcehttps://www.exploit-db.com/download/23725/
    titleFool's Workshop Owl's Workshop 1.0 glossaries/index.php file Parameter Arbitrary File Access
  • descriptionFool's Workshop Owl's Workshop 1.0 resultsignore.php Arbitrary File Accessa. CVE-2004-0303. Webapps exploit for php platform
    idEDB-ID:23727
    last seen2016-02-02
    modified2004-02-18
    published2004-02-18
    reporterG00db0y
    sourcehttps://www.exploit-db.com/download/23727/
    titleFool's Workshop Owl's Workshop 1.0 resultsignore.php Arbitrary File Access