NateOn Messenger Directory Listing Disclosure Vulnerability
BID:14100
Info
NateOn Messenger Directory Listing Disclosure Vulnerability
| Bugtraq ID: | 14100 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2005 12:00AM |
| Updated: | Jun 29 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Park Gyu Tae. |
| Vulnerable: |
Nate.com NateOn Messenger 3.0 |
| Not Vulnerable: | |
Discussion
NateOn Messenger Directory Listing Disclosure Vulnerability
NateOn messenger is prone to a remote directory listing information disclosure vulnerability. The issue manifests due to an unspecified input validation issue.
An attacker may exploit this issue to gain directory listings for a target user. Information that is harvested in this manner may be used to aid in further attacks against a target user.
NateOn messenger is prone to a remote directory listing information disclosure vulnerability. The issue manifests due to an unspecified input validation issue.
An attacker may exploit this issue to gain directory listings for a target user. Information that is harvested in this manner may be used to aid in further attacks against a target user.
Exploit / POC
NateOn Messenger Directory Listing Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NateOn Messenger Directory Listing Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.