AOH :: HP Unsorted C :: B06-5408.HTM

CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities



CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities
CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities



[vuln.sg] Vulnerability Research Advisory

CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities

by Tan Chew Keong
Release Date: 2006-10-24

Summary
-------
Two vulnerabilities have been found in CruiseWorks. When exploited, the vulnerabilities allow an authenticated user to retrieve arbitrary files accessible to the web server process and to execute arbitrary code with privileges of the IIS IUSR_MACHINE account.

Tested Versions
---------------
CruiseWorks Groupware version 1.09c and 1.09d.

Details
-------
http://vuln.sg/cruiseworks109d-en.html 
http://vuln.sg/cruiseworks109d-jp.html 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.