Exploitation Summary
EIP tracks 1 public exploit for CVE-2002-0786. PoCs published by Nomad Mobile Research Centre.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file read vulnerability in Critical Path's InJoin Directory Server via the iCon administrative web interface. By manipulating the LOG parameter, an authenticated attacker can disclose the contents of any file readable by the iCon process.
Description
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.
Exploits (1)
This exploit demonstrates an arbitrary file read vulnerability in Critical Path's InJoin Directory Server via the iCon administrative web interface. By manipulating the LOG parameter, an authenticated attacker can disclose the contents of any file readable by the iCon process.