22 lines
No EOL
919 B
Text
22 lines
No EOL
919 B
Text
source: https://www.securityfocus.com/bid/12752/info
|
|
|
|
Participate Enterprise is reported prone to multiple access validation vulnerabilities. These issues may allow remote attackers to disclose sensitive information and corrupt and delete data that can ultimately lead to a denial of service condition.
|
|
|
|
The following specific issues were identified:
|
|
|
|
An attacker can browse the directory tree and disclose sensitive information.
|
|
|
|
An attacker can rename arbitrary objects.
|
|
|
|
An attacker can delete arbitrary objects as well.
|
|
|
|
All versions of Participate Enterprise are considered vulnerable at the moment.
|
|
|
|
To browse the directory tree:
|
|
http://www.example.com/pe/repository/displaynavigator.jsp?rootFolder=101
|
|
|
|
To rename an object:
|
|
http://www.example.com/pe/repository/include/renamepopup.jsp?selectedObject=101
|
|
|
|
To delete an object:
|
|
http://www.example.com/pe/repository/displaydeletenavigator.jsp?selectedObjectsCSV=101 |