Managed Workplace Service Center Installation Information Disclosure Vulnerability
BID:27702
Info
Managed Workplace Service Center Installation Information Disclosure Vulnerability
| Bugtraq ID: | 27702 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0636 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2008 12:00AM |
| Updated: | Sep 08 2008 09:21PM |
| Credit: | Brook Powers is credited with discovering this vulnerability. |
| Vulnerable: |
Level Platforms Managed Workplace Service Center 6.x Level Platforms Managed Workplace Service Center 5.x Level Platforms Managed Workplace Service Center 4.x |
| Not Vulnerable: |
Level Platforms Managed Workplace Service Center 6.0 SP3 |
Discussion
Managed Workplace Service Center Installation Information Disclosure Vulnerability
Managed Workplace Service Center is prone to an information-disclosure vulnerability because the application fails to protect private information.
Attackers may exploit this issue to retrieve sensitive information that may aid in further attacks.
Managed Workplace Service Center is prone to an information-disclosure vulnerability because the application fails to protect private information.
Attackers may exploit this issue to retrieve sensitive information that may aid in further attacks.
Exploit / POC
Managed Workplace Service Center Installation Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
The following proof-of-concept URI is available:
http://www.example.com/About/SC_About.htm
An attacker can exploit this issue through a browser.
The following proof-of-concept URI is available:
http://www.example.com/About/SC_About.htm
Solution / Fix
Managed Workplace Service Center Installation Information Disclosure Vulnerability
Solution:
A vendor update is available. Please see the references for more information.
Solution:
A vendor update is available. Please see the references for more information.
References
Managed Workplace Service Center Installation Information Disclosure Vulnerability
References:
References: