CVE-2004-2493

UnknownEPSS 1.31%

Last modified

CVE-2004-2493 is a vulnerability of currently unknown severity. Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.

Description

Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.

Metrics

EPSS Probability
1.31%

67.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HitachiGroupmax World Wide Web2
HitachiGroupmax World Wide Web02_00
HitachiGroupmax World Wide Web02_20
HitachiGroupmax World Wide Web02_20_a
HitachiGroupmax World Wide Web02_31_i
HitachiGroupmax World Wide Web3
HitachiGroupmax World Wide Web03_00
HitachiGroupmax World Wide Web03_10_h
HitachiGroupmax World Wide Web03_11_b
HitachiGroupmax World Wide Web Desktop5
HitachiGroupmax World Wide Web Desktop05_00
HitachiGroupmax World Wide Web Desktop05_11_f
HitachiGroupmax World Wide Web Desktop05_11_i
HitachiGroupmax World Wide Web Desktop05_11_j
HitachiGroupmax World Wide Web Desktop6
HitachiGroupmax World Wide Web Desktop06_00
HitachiGroupmax World Wide Web Desktop06_50_b
HitachiGroupmax World Wide Web Desktop06_50_c
HitachiGroupmax World Wide Web Desktop06_51
HitachiGroupmax World Wide Web Desktop06_51_b
HitachiGroupmax World Wide Web Desktop06_51_c
HitachiGroupmax World Wide Web Desktop06_52
HitachiGroupmax World Wide Web Desktop06_52_b
HitachiGroupmax World Wide Web Desktopgold

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-2493?
Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.
How severe is CVE-2004-2493?
Severity scoring for CVE-2004-2493 is pending analysis. The EPSS model estimates a 1.31% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2493?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-2493?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST