Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-10/0366.html | vendor advisory mailing list |
http://www.securityfocus.com/bid/6048 | vdb entry vendor advisory |
http://www.iss.net/security_center/static/10473.php | patch vendor advisory vdb entry |