CVE-2004-1223

F-Secure Policy Manager <5.11.2810 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1223. PoCs published by [email protected].

AI-analyzed exploit summary This exploit leverages an input validation flaw in F-Secure Policy Manager's 'fsmsh.dll' CGI application to trigger an error message that discloses the software's installation path. The attack involves sending a malformed request to the DLL, resulting in an information leak.

Description

The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textremotewindows
https://www.exploit-db.com/exploits/24811

This exploit leverages an input validation flaw in F-Secure Policy Manager's 'fsmsh.dll' CGI application to trigger an error message that discloses the software's installation path. The attack involves sending a malformed request to the DLL, resulting in an information leak.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: F-Secure Policy Manager (version not specified)
No auth needed
Prerequisites: Network access to the target server · F-Secure Policy Manager with vulnerable 'fsmsh.dll' exposed
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18413
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110262921306862&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11869
Various Sources x_refsource_misc
http://www.oliverkarow.de/research/f-secure.txt

Scores

EPSS 0.0294
EPSS Percentile 85.7%

Details

Status published
Products (1)
f-secure/policy_manager 5.11
Published Jan 10, 2005
Tracked Since Feb 18, 2026