Vulnerabilities > CVE-2005-3163 - Unspecified vulnerability in Polipo

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
polipo
nessus

Summary

Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.

Nessus

NASL familyWeb Servers
NASL idPOLIPO_DIR_TRAVERSAL.NASL
descriptionThe remote host is running the Polipo caching web proxy. In addition to caching web pages, the software also functions as a web server for providing access to documentation, cached pages, etc. The built-in web server in the installed version of Polipo fails to filter directory traversal sequences from requests. By exploiting this issue, an attacker may be able to retrieve files located outside the local web root, subject to the privileges of the userid under which Polipo runs.
last seen2020-06-01
modified2020-06-02
plugin id19940
published2005-10-06
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/19940
titlePolipo < 0.9.9 Unspecified Traversal Arbitrary File Access