SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html | mailing list |
http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html | mailing list exploit vendor advisory |
http://www.securityfocus.com/bid/1402 | vdb entry |