Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4511. PoCs published by Jon Hart.
AI-analyzed exploit summary The entry describes multiple vulnerabilities in TANDBERG Video Communication Server, including file disclosure, server impersonation, and authentication bypass. It provides a specific example of a directory traversal attack to access sensitive files like /etc/passwd.
Description
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.
Exploits (1)
The entry describes multiple vulnerabilities in TANDBERG Video Communication Server, including file disclosure, server impersonation, and authentication bypass. It provides a specific example of a directory traversal attack to access sensitive files like /etc/passwd.