Bug: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user (WLB-2007030177 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user
 Credit: yearsilent
 Date: 2007.03.30
 CWE: CWE-noinfo (Show similar)
 CVE: CVE-2007-1642 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
Yes
No

"ManageEngine Firewall Analyzer is a web based firewall monitoring and log analysis tool that collects, analyses,
and reports information on enterprise-wide firewalls, proxy servers, and radius servers. "

a authorized user to the "firewall analyzer" can access any common file on the system, it is should not be
allowded

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com