Tivoli Directory Server ldacgi.exe Template Parameter Traversal Arbitrary File Access

medium Nessus Plugin ID 14191

Synopsis

The remote web server is prone to a directory traversal attack.

Description

The remote host is running IBM Tivoli's Directory Server, a lightweight LDAP server with a web frontend.

There is a directory traversal issue in the web frontend of this program, specifically in the 'ldacgi.exe' CGI. An attacker may exploit this flaw to read arbitrary files on the remote system with the privileges of the web server.

Solution

Apply 3.2.2 Fix Pack 4 / 4.1 Fix Pack 3 or later.

See Also

http://www.oliverkarow.de/research/IDS_directory_traversal.txt

https://seclists.org/fulldisclosure/2004/Aug/29

http://www-1.ibm.com/support/docview.wss?uid=swg1IR53631

Plugin Details

Severity: Medium

ID: 14191

File Name: tivoli_ldacgi_traversal.nasl

Version: 1.21

Type: remote

Family: CGI abuses

Published: 8/2/2004

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:ibm:tivoli_directory_server

Exploit Ease: No exploit is required

Exploited by Nessus: true

Vulnerability Publication Date: 8/2/2004

Reference Information

CVE: CVE-2004-2526

BID: 10841