Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-2526. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in IBM Tivoli Directory Server's web front-end. By manipulating the 'Template' parameter, an attacker can access sensitive files on the server, such as 'boot.ini', with the privileges of the 'ldap' user.
Description
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in IBM Tivoli Directory Server's web front-end. By manipulating the 'Template' parameter, an attacker can access sensitive files on the server, such as 'boot.ini', with the privileges of the 'ldap' user.