Intrusion Prevention

Ipswitch.Whatsup.Small.Business.Directory.Traversal

Description

This indicates an attack attempt against a directory traversal vulnerability in Ipswitch WhatsUp Small Business.
The vulnerability is caused by insufficient checking of user-supplied input. It allows a remote attacker to read arbitrary files outside the Web root by using "../" in a request.

Affected Products

WhatsUp Small Business 2004 Any version

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

No patch from the vendor is available as of this writing.

CVE References

CVE-2005-1939