Novell Sentinel Log Manager 1.2.0.1 Directory Traversal

2011.12.19
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

************************************************************** Vuln: Path Traversal Application: Sentinel Log Manager Vendor: Novell Version affected: <= 1.2.0.1 Website: http://www.novell.com/products/sentinel-log-manager/ Discovered By: Andrea Fabrizi Email: andrea.fabrizi@gmail.com Web: http://www.andreafabrizi.it ************************************************************** The latest version of Sentinel Log Manager is prone to a Directory Traversal, which makes it possible, for Authenticated Users, to access any system file. Testing environment: Sentinel Log Manager Appliance 1.2.0.1 Vulnerable URL: /novelllogmanager/FileDownload?filename=/opt/novell/sentinel_log_mgr/3rdparty/tomcat/temp/../../../../../../etc/passwd

References:

http://www.novell.com/products/sentinel-log-manager/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top