Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  SKForum XSS vuln.

  [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion

  ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting & 1 SQL Injection ] MultBugz

  [ GLSA 200604-02 ] Horde Application Framework: Remote code execution

From:silentw <silentw_(at)_gmail.com>
Date:05.04.2006
Subject:[Full-disclosure] WebEOC Vuln - more info

Hi Guys,

Doing a pen test I have come up with a WebEOC server. There are a few
vulns listed at:

http://secunia.com/advisories/16075/

specifically I am interested in :

"6) Sensitive information is exposed in URIs, stored in publicly
accessible configuration files, and in the HTML code returned to
users.

7) A design error allows malicious users to access parts of the
application that they should not have access to by directly specifying
the URL."

however I have been unable to find out what these files are called.
Any information from people would be great. ESi have a demo on their
site, but it involves pretending to be interested in buying it and
talking to their sales guys.. so I figured I would ask here first.

Cheers.
hf

--
parents will have to make sacrifices

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server