[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2571D31D42513640AE1632FEE100E0E402DD7499@hypercom.defense.local>
Date: Mon, 9 Mar 2009 09:36:23 -0500
From: "DDI_Vulnerability_Alert" <DDI.VulnerabilityAlert@...frontline.com>
To: <full-disclosure@...ts.grok.org.uk>
Subject: DDIVRT-2009-22 SMART Board Whiteboard Directory
Traversal Vulnerability
Title
-----
DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability
Severity
--------
High
Date Discovered
---------------
January 19th, 2009
Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: David Marshall and r@...$
Vulnerability Description
-------------------------
A directory traversal condition exists in SMART Web Server whereby
arbitrary files may be retrieved from this host's file system. Attackers
may leverage this issue to gain access to sensitive information stored
on this host.
Solution Description
--------------------
No patch is available at this time.
Tested Systems / Software (with versions)
------------------------------------------
Windows XP, SMART Board Whiteboard
Vendor Contact
--------------
Vendor Name: SMART Technologies ULC
Vendor Website: http://www2.smarttech.com/
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists