| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user |
| From: | support@fwanalyzer.com |
| Date: | 30 Mar 2007 07:06:38 -0000 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
We thank you for bringing this to our notice & apologize for any inconvenience this has caused. The reason for this problem is that we were passing the absolute path of the file in the URL. This has now been fixed by providing an randomly generated Identifier which is mapped to file. This fix is made available in our upcoming build 4030. Any users who would like to get an early access to this build can feel free to send us a request mail to <support at fwanalyzer dot com> Thanks & Regards AJ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ECHO_ADV_80$2007] Softerra Time-Assistant <= 6.2 (inc_dir) Remote File Inclusion Vulnerability, erdc |
|---|---|
| Next by Date: | ANI Zeroday, Third Party Patch, Marc Maiffret |
| Previous by Thread: | Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user, support |
| Next by Thread: | Remote File Include In copyright © James Coyle; JCcorp, RaeD Hasadya |
| Indexes: | [Date] [Thread] [Top] [All Lists] |