tam-file-retrieval.txt...

- AV AC AU C I A
发布: 2006-02-06
修订: 2025-04-13

On December 1st, while conducting a penetration test of a TAM enabled web application, VSR identified a vulnerability in Tivoli Web Server Plug-in which is a component of Tivoli Access Manager (TAM). This flaw allows an authenticated attacker to retrieve files (which reside outside of the web root) from the web server on which the plug-in resides. It is possible to retrieve any file or list any directory which is readable by the web server software.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息