Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user Mar 30 2007 07:06AM
support fwanalyzer com
We thank you for bringing this to our notice & apologize for any inconvenience this has caused.

The reason for this problem is that we were passing the absolute path of the file in the URL. This has now been fixed by providing an randomly generated Identifier which is mapped to file. This fix is ma...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus