OpenNMS 'fileName' Parameter Arbitrary File Disclosure Vulnerability
BID:67939
Info
OpenNMS 'fileName' Parameter Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 67939 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 03 2014 12:00AM |
| Updated: | Jun 03 2014 12:00AM |
| Credit: | Martin Laercher |
| Vulnerable: |
OpenNMS OpenNMS 1.12.7 |
| Not Vulnerable: |
OpenNMS OpenNMS 1.13.3 OpenNMS OpenNMS 1.12.8 OpenNMS OpenNMS 1.10.14 |
Discussion
OpenNMS 'fileName' Parameter Arbitrary File Disclosure Vulnerability
OpenNMS is prone to an arbitrary file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
OpenNMS 1.12.7 is vulnerable.
OpenNMS is prone to an arbitrary file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
OpenNMS 1.12.7 is vulnerable.
References
OpenNMS 'fileName' Parameter Arbitrary File Disclosure Vulnerability
References:
References: