CVE-2004-2061 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 5.7% (pctl 93)
Patch early
A public exploit exists.
Description
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.7% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-918 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-07-27 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| risearch | risearch |
| risearch | risearch pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RiSearch 0.99 /RiSearch Pro 3.2.6 - show.pl Open Proxy Relay | 2004-07-27 |
| exploit-db | RiSearch 0.99 /RiSearch Pro 3.2.6 - show.pl Arbitrary File Access | 2004-07-27 |
References
- http://marc.info/?l=bugtraq&m=109095196526490&w=2
- http://secunia.com/advisories/12173
- http://securitytracker.com/id?1010788
- http://www.osvdb.org/8265
- http://www.osvdb.org/8266
- http://www.securityfocus.com/bid/10812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16817
- http://marc.info/?l=bugtraq&m=109095196526490&w=2
- http://secunia.com/advisories/12173
- http://securitytracker.com/id?1010788
- http://www.osvdb.org/8265
- http://www.osvdb.org/8266
- http://www.securityfocus.com/bid/10812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16817
→ the Explorer · watch your stack · NVD