lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20101217141107.30822.qmail@securityfocus.com> Date: 17 Dec 2010 14:11:07 -0000 From: wsn1983@...il.com To: bugtraq@...urityfocus.com Subject: Alt-N WebAdmin Source Code Disclosure Vulnerable: v3.3.3 Vendor: www.altn.com Category: Environment Error Vulnerable ======== Alt-N WebAdmin 3.3.3 U-Mail for Windows V9.8 U-Mail GateWay for Windows V9.8 Details: ========= A source code disclosure vulnerability exists with Alt-N WebAdmin Server. Remote attacker can be exploited to disclose the source code by appending "%2e" or "%20" to a URI. Test on U-Mail for Windows V9.8 and U-Mail GateWay for Windows V9.8 POC: ========= http://ip:1000/login.wdm%20 http://ip:1000/login.wdm%2e Reference: ========= www.comingchina.com/download.html http://www.nansec.com/