Информационная безопасность
[RU] switch to English


Дополнительная информация

  Cводка уязвимостей безопасности в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  appRain CMF v0.1.5 - Multiple Web Vulnerabilities

  SASHA v0.2.0 Mutiple XSS

  PHP Booking Calendar 10e XSS

  [SECURITY] [DSA 2365-1] dtc security update

From:Andrea Fabrizi <andrea.fabrizi_(at)_gmail.com>
Date:26 декабря 2011 г.
Subject:Novell Sentinel Log Manager <=1.2.0.1 Path Traversal

**************************************************************
Vuln: Path Traversal
Application: Sentinel Log Manager
Vendor: Novell
Version affected: <= 1.2.0.1
Website: http://www.novell.com/products/sentinel-log-manager/
Discovered By: Andrea Fabrizi
Email: [email protected]
Web: http://www.andreafabrizi.it
**************************************************************

The latest version of Sentinel Log Manager is prone to a Directory
Traversal, which makes it possible, for Authenticated Users, to access
any system file.

Testing environment: Sentinel Log Manager Appliance 1.2.0.1

Vulnerable URL:
/novelllogmanager/FileDownload?filename=/opt/novell/sentinel_log_mgr/3rdparty/tom
cat/temp/../../../../../../etc/passwd

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород