The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://procheckup.com/Vulnerability_PR06-08.php | exploit |
http://www.securitytracker.com/id?1019005 | vdb entry |
http://www.vupen.com/english/advisories/2007/4040 | vdb entry |
http://www.securityfocus.com/archive/1/484467/100/0/threaded | mailing list |
http://procheckup.com/Vulnerability_PR06-09.php | exploit |
http://secunia.com/advisories/27840 | third party advisory patch vendor advisory |