Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1223. PoCs published by [email protected].
AI-analyzed exploit summary This exploit leverages an input validation flaw in F-Secure Policy Manager's 'fsmsh.dll' CGI application to trigger an error message that discloses the software's installation path. The attack involves sending a malformed request to the DLL, resulting in an information leak.
Description
The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.
Exploits (1)
This exploit leverages an input validation flaw in F-Secure Policy Manager's 'fsmsh.dll' CGI application to trigger an error message that discloses the software's installation path. The attack involves sending a malformed request to the DLL, resulting in an information leak.