Exploit IBM Tivoli Directory Server 3.2.2/4.1 - LDACGI Directory Traversal

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
24345
Проверка EDB
  1. Пройдено
Автор
ANONYMOUS
Тип уязвимости
REMOTE
Платформа
WINDOWS
CVE
cve-2004-2526
Дата публикации
2004-08-02
IBM Tivoli Directory Server 3.2.2/4.1 - LDACGI Directory Traversal
Код:
source: https://www.securityfocus.com/bid/10841/info

IBM Tivoli Directory Server is reported to contain a directory traversal vulnerability in its web front-end application.

This issue presents itself due to insufficient sanitization of user-supplied data.

This issue allows remote attackers to view potentially sensitive files on the server that are accessible to the 'ldap' user. This may aid an attacker in conducting further attacks against the vulnerable computer.

Versions 3.2.2, and 4.1 are reported vulnerable.

http://www.example.com/ldap/cgi-bin/ldacgi.exe?Action=Substitute&Template=../../../../../boot.ini&Sub=LocalePath&LocalePath=enus1252
 
Источник
www.exploit-db.com

Похожие темы