Juniper Networks Secure Access 2000 Web Root Path Disclosure Vulnerability
BID:28037
Info
Juniper Networks Secure Access 2000 Web Root Path Disclosure Vulnerability
| Bugtraq ID: | 28037 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1181 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Richard Brain of ProCheckUp Ltd. is credited with discovering this vulnerability. |
| Vulnerable: |
Juniper Secure Access 2000 5.5R1 Build 11711 Juniper Secure Access 2000 0 |
| Not Vulnerable: |
Juniper Secure Access 2000 6.0R1 |
Discussion
Juniper Networks Secure Access 2000 Web Root Path Disclosure Vulnerability
Juniper Networks Secure Access 2000 is prone to a path-disclosure vulnerability.
Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks.
Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
Juniper Networks Secure Access 2000 is prone to a path-disclosure vulnerability.
Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks.
Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
Exploit / POC
Juniper Networks Secure Access 2000 Web Root Path Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
The following example URIs are available:
https://www.example.com/dana-na/auth/remediate.cgi?action=&step=preauth
https://www.example.com/dana-na/auth/remediate.cgi?step=preauth
Attackers can use a browser to exploit this issue.
The following example URIs are available:
https://www.example.com/dana-na/auth/remediate.cgi?action=&step=preauth
https://www.example.com/dana-na/auth/remediate.cgi?step=preauth
Solution / Fix
Juniper Networks Secure Access 2000 Web Root Path Disclosure Vulnerability
Solution:
The vendor has released Secure Access 2000 6.0R1 to address this issue. Please see the references for more information.
Solution:
The vendor has released Secure Access 2000 6.0R1 to address this issue. Please see the references for more information.
References
Juniper Networks Secure Access 2000 Web Root Path Disclosure Vulnerability
References:
References:
- Juniper Networks Homepage (Juniper Networks)
- Secure Access 2000 Homepage (Juniper Networks)
- PR07-42: Webroot disclosure on Juniper Networks Secure Access 2000 (ProCheckUp Research
) - PR07-42: Webroot disclosure on Juniper Networks Secure Access 2000 (ProCheckUp)