5
CVSSv2

CVE-2004-2526

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and previous versions allows remote malicious users to view arbitrary files via a .. (dot dot) in the Template parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli directory server

ibm tivoli directory server 3.2.2

Exploits

source: wwwsecurityfocuscom/bid/10841/info IBM Tivoli Directory Server is reported to contain a directory traversal vulnerability in its web front-end application This issue presents itself due to insufficient sanitization of user-supplied data This issue allows remote attackers to view potentially sensitive files on the server that a ...