Vulnerabilities > CVE-2002-1559 - Unspecified vulnerability in Research Systems Inc. ION Script 1.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ION Script 1.4 Remote File Disclosure Vulnerability. CVE-2002-1559. Webapps exploit for cgi platform |
id | EDB-ID:21979 |
last seen | 2016-02-02 |
modified | 2002-11-01 |
published | 2002-11-01 |
reporter | Zero X |
source | https://www.exploit-db.com/download/21979/ |
title | ION Script 1.4 - Remote File Disclosure Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | ION_P.NASL |
description | The ion-p.exe exists on this web server. Some versions of this file are vulnerable to remote exploit. An attacker, exploiting this vulnerability, may be able to gain access to confidential data and/or escalate their privileges on the web server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11729 |
published | 2003-06-11 |
reporter | This script is Copyright (C) 2003-2018 John Lampe |
source | https://www.tenable.com/plugins/nessus/11729 |
title | ION ion-p.exe page Parameter Traversal Arbitrary File Retrieval |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0447.html
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0447.html
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0448.html
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0448.html
- http://www.iss.net/security_center/static/10518.php
- http://www.iss.net/security_center/static/10518.php
- http://www.securityfocus.com/bid/6091
- http://www.securityfocus.com/bid/6091