peter bassill · operator
$ cve CVE-2004-2061 JSON

CVE-2004-2061 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 5.7% (pctl 93)

Patch early

A public exploit exists.

Description

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.7% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploityes
Published2004-07-27
Last modified2026-06-16

Affected (2)

VendorProduct
risearchrisearch
risearchrisearch pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD