Netbula Anyboard Information Disclosure Vulnerability
BID:8490
Info
Netbula Anyboard Information Disclosure Vulnerability
| Bugtraq ID: | 8490 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2003 12:00AM |
| Updated: | Aug 25 2003 12:00AM |
| Credit: | The discovery of this issue has been credited to Cyber Talon <[email protected]>. |
| Vulnerable: |
Netbula Anyboard 9.9.5 6 |
| Not Vulnerable: | |
Discussion
Netbula Anyboard Information Disclosure Vulnerability
A vulnerability has been reported in Netbula Anyboard that may allow a remote attacker to gain access to sensitive data. This problem is due to an information disclosure issue that can be triggered by an attacker sending specific HTTP requests to a vulnerable host. This will result in sensitive information about the system being revealed to the attacker.
This vulnerability may allow an attack to gather sensitive information in order to launch further attacks against a vulnerable system.
A vulnerability has been reported in Netbula Anyboard that may allow a remote attacker to gain access to sensitive data. This problem is due to an information disclosure issue that can be triggered by an attacker sending specific HTTP requests to a vulnerable host. This will result in sensitive information about the system being revealed to the attacker.
This vulnerability may allow an attack to gather sensitive information in order to launch further attacks against a vulnerable system.
Exploit / POC
Netbula Anyboard Information Disclosure Vulnerability
The following proof of concept has been provided:
http://www.example.com/cgi-bin/anyboard.cgi/?cmd=sinfo&all=1
The following proof of concept has been provided:
http://www.example.com/cgi-bin/anyboard.cgi/?cmd=sinfo&all=1
Solution / Fix
Netbula Anyboard Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.