Vulnerability CVE-2011-1424


Published: 2011-05-24   Modified: 2012-02-13

Description:
The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.

See advisories in our WLB2 database:
Topic
Author
Date
Low
EMC SourceOne ASP.NET application tracing information disclosure vulnerability
Security_Alert e...
25.05.2011

Type:

CWE-16

(Configuration)

CVSS2 => (AV:N/AC:M/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
EMC -> Sourceone email management 

 References:
http://securityreason.com/securityalert/8258
http://www.securityfocus.com/archive/1/518003/100/0/threaded

Copyright 2024, cxsecurity.com

 

Back to Top