viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/350419/30/21610/threaded | mailing list |
http://secunia.com/advisories/10689 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1008799 | vdb entry |
http://www.osvdb.org/3680 | vdb entry |
http://securityreason.com/securityalert/3354 | third party advisory |
http://www.securityfocus.com/bid/9460 | vdb entry |