CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities

2006.10.31
Risk: High
Local: No
Remote: Yes
CWE: N/A

[vuln.sg] Vulnerability Research Advisory CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities by Tan Chew Keong Release Date: 2006-10-24 Summary ------- Two vulnerabilities have been found in CruiseWorks. When exploited, the vulnerabilities allow an authenticated user to retrieve arbitrary files accessible to the web server process and to execute arbitrary code with privileges of the IIS IUSR_MACHINE account. Tested Versions --------------- CruiseWorks Groupware version 1.09c and 1.09d. Details ------- http://vuln.sg/cruiseworks109d-en.html http://vuln.sg/cruiseworks109d-jp.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top