exploit-db-mirror/exploits/windows/remote/24345.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

11 lines
No EOL
656 B
Text

source: https://www.securityfocus.com/bid/10841/info
IBM Tivoli Directory Server is reported to contain a directory traversal vulnerability in its web front-end application.
This issue presents itself due to insufficient sanitization of user-supplied data.
This issue allows remote attackers to view potentially sensitive files on the server that are accessible to the 'ldap' user. This may aid an attacker in conducting further attacks against the vulnerable computer.
Versions 3.2.2, and 4.1 are reported vulnerable.
http://www.example.com/ldap/cgi-bin/ldacgi.exe?Action=Substitute&Template=../../../../../boot.ini&Sub=LocalePath&LocalePath=enus1252