header-logo
Suggest Exploit
vendor:
WebAdmin
by:
SecurityFocus
6.4
CVSS
MEDIUM
Remote File Access
22
CWE
Product Name: WebAdmin
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

Alt-N WebAdmin Remote File Access Vulnerability

Alt-N WebAdmin allows a remote user to access files that they should not be able to access. The remote user can submit an HTTP request that will return the contents of any webserver-readable file on the system. NOTE: The user must have administrative privileges in WebAdmin to access these files.

Mitigation:

Ensure that only authorized users have administrative privileges in WebAdmin.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/7438/info

Alt-N WebAdmin allows a remote user to access files that they should not be able to access. The remote user can submit an HTTP request that will return the contents of any webserver-readable file on the system.

NOTE: The user must have administrative privileges in WebAdmin to access these files.

http://server/WebAdmin.dll?Session=X&Program=MDaemon&Directory:Name=C:\WINNT&File:Name=WIN.INI&View=ViewFile