OSVDB ID: 28123

Title: Alt-N WebAdmin logfile_view.wdm file Parameter Traversal Arbitrary File Access

Info

Disclosure

Aug 21, 2006

Discovery

Unknown

Dates

Exploit

Aug 21, 2006

Solution

Unknown

Description

WebAdmin contains a flaw that allows a remote attacker to disclose contain of a file outside of the web path. The issue is due to 'logfile_view.wdm' not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'file' variable(s).

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality
Exploit: Exploit Public
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 3.25 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Alt-N Technologies

WebAdmin

3.2.3
3.2.4

References

Credit

  • TTG - releasesteklow.com -


Direct URL: http://osvdb.org/28123