IBM Lotus Domino HTTP webadmin.nsf Directory Traversal Vulnerability

The following proof of concept has been provided:
1)Go to http://www.example.com/webadmin.nsf
2)Go to "Files" tab
3)From the "Tools" menu select to create a "new" folder
4)As the name of the new folder enter "/../../../../../../pr00f"

or

"/../../../../windows/win.ini"


 

Privacy Statement
Copyright 2010, SecurityFocus