about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SonicWALL Global VPN Client Log File Remote Format String Vulnerability


Title SonicWALL Global VPN Client Log File Remote Format String Vulnerability
Published 2009-05-26-12:00AM
Updated 2009-05-26-05:10PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  lofi42 from SEC Consult
Vulnerable  SonicWALL Global VPN Client 4.0 251e Standard
SonicWALL Global VPN Client 4.0 251e Enhanced
Not Vulnerable  
Code  The following proofs of concept are available:1. CFS: Add example.com to your "Forbidden Domains" and access http://www.example.com/%s%s%s%s%s%s/.2. GroupVPN: Establish a GroupVPN Tunnel and enter at the XAUTH Username %s%s%s%s%s.3. Webfrontend: Enter at the Login Page of your SonicWALL as Username %s%s%s%s%s
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 05:30:06 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Jojo naked sex filem lara datta php root csrss PHP-CGI 0. www.chinay p...Fimage shakila im www *** 89 Nayanthara admin/auth xvideos.co www0890com Noelia www.quanji Martin xvideos.co guest book sxe www.golf88 mambo Remo product_de Fullysex www.localm www.hotsex iiruvyxaru PHP-NUKE.h chatmaster Wwwhotgirl WWW.hotsex php root FreeBSD 5. trishaboth php-nuke 2 hwty.net news for c www.xxx.co xsflower.c dfhyj X exploits news for C Tamil actr Sexy.89 xxxtarjan PaFileDB www.hdaz.c 200/compon px101.com news for c