Trend Micro Interscan Viruswall Configurations Modification Vulnerability
BID:2859
Info
Trend Micro Interscan Viruswall Configurations Modification Vulnerability
| Bugtraq ID: | 2859 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2001 12:00AM |
| Updated: | Jun 12 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by SNS Advisory <[email protected]> on June 12, 2001. |
| Vulnerable: |
Trend Micro InterScan VirusWall for Windows NT 3.51 |
| Not Vulnerable: | |
Discussion
Trend Micro Interscan Viruswall Configurations Modification Vulnerability
A remote user could utilize the administrator functions of Interscan Viruswall without providing authentication credentials. This may allow the user to make configuration changes when submitting specially crafted URLs to the host.
A remote user could utilize the administrator functions of Interscan Viruswall without providing authentication credentials. This may allow the user to make configuration changes when submitting specially crafted URLs to the host.
Exploit / POC
Trend Micro Interscan Viruswall Configurations Modification Vulnerability
http://VirusWall/interscan/cgi-bin/interscan.dll
http://VirusWall/interscan/cgi-bin/interscan.dll
References
Trend Micro Interscan Viruswall Configurations Modification Vulnerability
References:
References:
- InterScan VirusWall Product Home Page (Trend Micro)