OSVDB ID: 28122

Title: Alt-N WebAdmin configfile_view.wdm file Parameter Traversal Arbitrary File Access

Info

Disclosure

Aug 21, 2006

Discovery

Unknown

Dates

Exploit

Aug 21, 2006

Solution

Unknown

Description

WebAdmin contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when calling configfile_view.wdm with a 'file' variable containing dircetory traversal sequences in order to point to an existing file, which will disclose the contain of the file resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality
Exploit: Exploit Public
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 3.25 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Alt-N Technologies

WebAdmin

3.2.3
3.2.4

References

Credit

  • TTG - releasesteklow.com -


Direct URL: http://osvdb.org/28122