Title : Trend Micro OfficeScan Remote Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2008-2711 CVE ID : CVE-2008-2439 CWE ID : CWE-22
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-02
Technical Description
A vulnerability has been identified in various Trend Micro products, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "OfficeScanNT Listener" service when processing user-supplied requests, which could be exploited to retrieve arbitrary files from an affected system via directory traversal attacks.