vendor:
ION Script
by:
SecurityFocus
7.5
CVSS
HIGH
Arbitrary File Disclosure
200
CWE
Product Name: ION Script
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: UNIX
2002
ION Script Arbitrary File Disclosure Vulnerability
By sending a malicious HTTP request to a webserver running the vulnerable ION Script package, it is possible for a remote attacker to disclose arbitrary webserver readable files. As webservers are often run with high privileges, it may be possible to disclose sensitive system files. Exploiting this issue may allow an attacker to gain information required to launch further attacks against the target system.
Mitigation:
Ensure that all web applications are up to date and patched with the latest security updates.