Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WWWIsis File Disclosure Vulnerability

WWWIsis provides a web interface for accessing ISIS databases. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.

A file disclosure vulnerability exists in WWWIsis. This may enable a remote attacker to disclose the contents of arbitrary web-readable files. This is due to insufficient validation of user-supplied input.

This issue has been reported for 3.x versions. Other versions are not affected by this vulnerability. Additionally, JavaISIS and other tools based on WWWIsis may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus