Vulnerabilities > CVE-2004-2061 - Server-Side Request Forgery (SSRF) vulnerability in Risearch and Risearch PRO

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
risearch
CWE-918
critical
nessus
exploit available

Summary

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

Vulnerable Configurations

Part Description Count
Application
Risearch
2

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionRiSearch 0.99 /RiSearch Pro 3.2.6 show.pl Arbitrary File Access. CVE-2004-2061. Remote exploit for cgi platform
    idEDB-ID:24327
    last seen2016-02-02
    modified2004-07-27
    published2004-07-27
    reporterPhil Robinson
    sourcehttps://www.exploit-db.com/download/24327/
    titleRiSearch 0.99 /RiSearch Pro 3.2.6 show.pl Arbitrary File Access
  • descriptionRiSearch 0.99 /RiSearch Pro 3.2.6 show.pl Open Proxy Relay. CVE-2004-2061. Remote exploit for cgi platform
    idEDB-ID:24326
    last seen2016-02-02
    modified2004-07-27
    published2004-07-27
    reporterPhil Robinson
    sourcehttps://www.exploit-db.com/download/24326/
    titleRiSearch 0.99 /RiSearch Pro 3.2.6 show.pl Open Proxy Relay

Nessus

  • NASL familyCGI abuses
    NASL idRISEARCH_ARBITRARY_FILE_ACCESS.NASL
    descriptionThe remote host appears to be running RiSearch, a local search engine. This version contains an information disclosure vulnerability. Passing a local file URI to
    last seen2020-06-01
    modified2020-06-02
    plugin id14222
    published2004-08-04
    reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14222
    titleRiSearch show.pl Arbitrary File Access
  • NASL familyCGI abuses
    NASL idRISEARCH_OPEN_PROXY.NASL
    descriptionThe remote host seems to be running RiSearch, a local search engine. There is a flaw in the CGI
    last seen2020-06-01
    modified2020-06-02
    plugin id14180
    published2004-08-02
    reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14180
    titleRiSearch show.pl Open Proxy Relay