Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | The WebConnect 6.4.4 and 6.5 contains several vulnerabilities |
|---|---|
| Date: | Sun, 20 Feb 2005 23:10:54 +0100 |
The WebConnect 6.4.4 and 6.5 contains several vulnerabilities such as: - Denial of Service when requesting an DOS Device in Path Name - Reading of files outside webroot (Directory traversal) Requesting "DOS Device in Path Name" Denial of Service When requesting a DOS device in the URL the server will stop responding to any further requests before a manual restart of service has been made. This attack can be preformed on both the client website and the administration interface. Vulnerable versions: - WebConnect 6.4.4 (Possible previous versions) - WebConnect 6.5 CERT response: - VU#552561 CAN-2004-0466 Reading of files outside webroot (Directory traversal) When sending a specially crafted request to the server it is possible to read files outside the webroot. Since the service as default runs with system rights, this could give access to the entire partition that WebConnect are installed on. Vulnerable versions: - WebConnect 6.4.4 (Possible previous versions) CERT response: - VU#628411 CAN-2004-0465 Read the full advisory for both the vulnerabilities at: http://www.cirt.dk/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Combining Hashes, Joel Maslak |
|---|---|
| Next by Date: | [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection, pokley |
| Previous by Thread: | [NOBYTES.COM: #5] iGeneric eShop 1.2 - Information Disclosure & Possible SQL Injection, John Cobb |
| Next by Thread: | [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection, pokley |
| Indexes: | [Date] [Thread] [Top] [All Lists] |