Vulnerabilities > CVE-2004-2526 - Directory Traversal vulnerability in IBM Tivoli Directory Server LDACGI

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ibm
nessus
exploit available

Summary

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

Vulnerable Configurations

Part Description Count
Application
Ibm
3

Exploit-Db

descriptionIBM Tivoli Directory Server 3.2.2/4.1 LDACGI Directory Traversal Vulnerability. CVE-2004-2526. Remote exploit for windows platform
idEDB-ID:24345
last seen2016-02-02
modified2004-08-02
published2004-08-02
reporteranonymous
sourcehttps://www.exploit-db.com/download/24345/
titleIBM Tivoli Directory Server 3.2.2/4.1 LDACGI Directory Traversal Vulnerability

Nessus

NASL familyCGI abuses
NASL idTIVOLI_LDACGI_TRAVERSAL.NASL
descriptionThe remote host is running IBM Tivoli
last seen2020-06-01
modified2020-06-02
plugin id14191
published2004-08-02
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14191
titleTivoli Directory Server ldacgi.exe Template Parameter Traversal Arbitrary File Access