Vulnerability Details CVE-2004-0303
OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.089
EPSS Ranking 92.2%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2004-0303
-
cpe:2.3:a:fools_workshop:owls_workshop:1.0