IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
BID:15291
Info
IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
| Bugtraq ID: | 15291 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1939 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 03 2005 12:00AM |
| Credit: | Discovery credited to Dennis Rand. |
| Vulnerable: |
Ipswitch WhatsUp Small Business 2004 |
| Not Vulnerable: | |
Discussion
IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
IPSwitch WhatsUp Small Business 2004 is prone to a directory traversal vulnerability. Successful exploitation could allow a remote attacker to gain access to files outside the Web root. Sensitive information may be obtained in this manner.
IPSwitch WhatsUp Small Business 2004 is prone to a directory traversal vulnerability. Successful exploitation could allow a remote attacker to gain access to files outside the Web root. Sensitive information may be obtained in this manner.
Exploit / POC
IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
An exploit is not required. The following proof of concept is available:
http://[address of server]:8022/../../../../../../../../../../../boot.ini
An exploit is not required. The following proof of concept is available:
http://[address of server]:8022/../../../../../../../../../../../boot.ini
Solution / Fix
IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
References:
References: