Bugtraq mailing list archives

Re: Nfuse reveals full path


From: rjmitchell () nisource com
Date: Mon, 2 Jul 2001 07:15:31 -0400

Greetings,

What version of NFuse are you running? I tested this with version 1.51 and here
is the error I saw:

There was an error:
This operation requires user credentials to be specified. The following session
field was not set: NFUSE_USER

As you can see, no revealing of the path.

Regards,

- Rick Mitchell
Systems Engineer
Columbia Gas Transmission





sween () modelm org on 07/02/2001 06:19:51 AM
Please respond to sween () modelm org


To: bugtraq () securityfocus com
cc:

Subject: Nfuse reveals full path




I googled for a bit, and didn't find it after I stumbled upon it.
/me apologizes if this is common knowledge

http://pooter/nfuse/asp/launch.asp?


Produces:

There was an error:
The Citrix HTML template contains tags that require an app to be specified
via the NFuse_Application session field, but this session field was not
set.

The template with the error is located at

D:\Inetpub\wwwroot\nfuse\asp\template.ica



--

 ---  -sween
| M | http://www.modelm.org
 ---  "force feedback computing since 1984."





Current thread: