Back to list
[vuln.sg] CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities
Oct 24 2006 09:16AM
vulnpost-remove vuln sg
[vuln.sg] Vulnerability Research Advisory
CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities
by Tan Chew Keong
Release Date: 2006-10-24
Two vulnerabilities have been found in CruiseWorks. When exploited, the vulnerabilities allow an authenticated user to retrieve arbitrary files accessible to the web server process and to execute arbitrary code with privileges of the IIS IUSR_MACHINE account.
CruiseWorks Groupware version 1.09c and 1.09d.
[ reply ]
Copyright 2010, SecurityFocus