lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <200903091444.n29EiNVN016944@www3.securityfocus.com> Date: Mon, 9 Mar 2009 08:44:23 -0600 From: ddivulnalert@...frontline.com To: bugtraq@...urityfocus.com Subject: DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability Title ----- DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability Severity -------- High Date Discovered --------------- January 19th, 2009 Discovered By ------------- Digital Defense, Inc. Vulnerability Research Team Credit: David Marshall and r@...$ Vulnerability Description ------------------------- A directory traversal condition exists in SMART Web Server whereby arbitrary files may be retrieved from this host's file system. Attackers may leverage this issue to gain access to sensitive information stored on this host. Solution Description -------------------- No patch is available at this time. Tested Systems / Software (with versions) ------------------------------------------ Windows XP, SMART Board Whiteboard Vendor Contact -------------- Vendor Name: SMART Technologies ULC Vendor Website: http://www2.smarttech.com/
Powered by blists - more mailing lists