Vulnerabilities > CVE-2006-4681 - Directory Traversal vulnerability in IBM Director 3.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter. This vulnerability is addressed in the following product release: IBM, Director, 5.10
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | IBM Director < 5.10 (Redirect.bat) Directory Transversal Vulnerability. CVE-2006-4681. Remote exploit for windows platform |
file | exploits/windows/remote/2320.txt |
id | EDB-ID:2320 |
last seen | 2016-01-31 |
modified | 2006-09-07 |
platform | windows |
port | 411 |
published | 2006-09-07 |
reporter | Daniel Clemens |
source | https://www.exploit-db.com/download/2320/ |
title | IBM Director < 5.10 Redirect.bat Directory Transversal Vulnerability |
type | remote |
References
- ftp://ftp.software.ibm.com/pc/pccbbs/pc_servers_pdf/dir5.10_docs_relnotes.pdf
- http://secunia.com/advisories/21802
- http://securitytracker.com/id?1016815
- http://www.securityfocus.com/bid/19898
- http://www.vupen.com/english/advisories/2006/3532
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28836
- https://www.exploit-db.com/exploits/2320