
Topic: |
ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user |
Credit: |
yearsilent |
Date: |
2007.03.30 |
CWE: |
CWE-noinfo (Show similar)
|
CVE: |
CVE-2007-1642 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| Medium |
Yes |
| No |
"ManageEngine Firewall Analyzer is a web based firewall monitoring and log analysis tool that collects, analyses,
and reports information on enterprise-wide firewalls, proxy servers, and radius servers. "
a authorized user to the "firewall analyzer" can access any common file on the system, it is should not be
allowded
[ ASCII VERSION ]
|