Borland StarTeam 'performCheckoutFile()' Function Arbitrary File Disclosure Vulnerability
BID:67767
Info
Borland StarTeam 'performCheckoutFile()' Function Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 67767 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | No |
| Published: | May 05 2014 12:00AM |
| Updated: | May 05 2014 12:00AM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
Borland Starteam 0 |
| Not Vulnerable: | |
Discussion
Borland StarTeam 'performCheckoutFile()' Function Arbitrary File Disclosure Vulnerability
Borland StarTeam is prone to an arbitrary file-disclosure vulnerability.
Exploiting this issue could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Borland StarTeam is prone to an arbitrary file-disclosure vulnerability.
Exploiting this issue could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Exploit / POC
Borland StarTeam 'performCheckoutFile()' Function Arbitrary File Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Borland StarTeam 'performCheckoutFile()' Function Arbitrary File Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Borland StarTeam 'performCheckoutFile()' Function Arbitrary File Disclosure Vulnerability
References:
References:
- StarTeam Homepage (Borland)
- (0Day) Borland StarTeam Web Server AttachmentService performCheckoutFile Remote (Zero Day Initiative)