Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/28037 | vdb entry |
http://securityreason.com/securityalert/3719 | third party advisory |
http://www.securityfocus.com/archive/1/488919/100/0/threaded | mailing list |
http://www.securitytracker.com/id?1019526 | vdb entry |