bugtraq
[Top] [All Lists]

Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authoriz

To: bugtraq@securityfocus.com
Subject: Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user
From: support@fwanalyzer.com
Date: 30 Mar 2007 07:06:38 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
We thank you for bringing this to our notice & apologize for any inconvenience 
this has caused.

The reason for this problem is that we were passing the absolute path of the 
file in the URL. This has now been fixed by providing an randomly generated 
Identifier which is mapped to file. This fix is made available in our upcoming 
build 4030. Any users who would like to get an early access to this build can 
feel free to send us a request mail to <support at fwanalyzer dot com>

Thanks & Regards
AJ

<Prev in Thread] Current Thread [Next in Thread>