|
|
| |
| The Remote Console Applet that ships with the Instant ASP software suite contains an access validation error that allows an attacker to retrieve any file on the remote system. This includes sensitive configuration files for Instant ASP as well as any other file on the remote host (SAM, PASSWD, SHADOW, et. al). |
| |
Credit:
The information has been provided by Alan "ph33r" Neville.
|
| |
Vulnerable systems:
* The Remote Console Applet version 1.0.9 and prior
Exploit:
Simply point a web browser at
http://<hostname>:9095/../../../../../../etc/passwd
Solution:
Halcyon Software was contacted regarding this problem on the 8th of December 2002. There is no patch for this problem at present.
|
|
|
|
|
|
|
|