Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

[vuln.sg] CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities
From: TAN Chew Keong <vulnpost-remove () vuln sg>
Date: Tue, 24 Oct 2006 13:17:02 +0800

[vuln.sg] Vulnerability Research Advisory

CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities

by Tan Chew Keong
Release Date: 2006-10-24

Summary
-------
Two vulnerabilities have been found in CruiseWorks. When exploited, the
vulnerabilities allow an authenticated user to retrieve arbitrary files
accessible to the web server process and to execute arbitrary code with
privileges of the IIS IUSR_MACHINE account.

Tested Versions
---------------
CruiseWorks Groupware version 1.09c and 1.09d.

Details
-------
http://vuln.sg/cruiseworks109d-en.html
http://vuln.sg/cruiseworks109d-jp.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
  • [vuln.sg] CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities TAN Chew Keong (Oct 24)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault