Bugtraq mailing list archives

ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user


From: yearsilent () yahoo com
Date: 22 Mar 2007 09:56:35 -0000

"ManageEngine Firewall Analyzer is a web based firewall monitoring and log analysis tool that collects, analyses, and 
reports information on enterprise-wide firewalls, proxy servers, and radius servers. "

a authorized user to the "firewall analyzer" can access any common file on the system, it is should not be allowded


Current thread: