Sambar Server 5.x - Information Disclosure

Author: gregory Le Bras
type: remote
platform: windows
port: 
date_added: 2003-03-27  
date_updated: 2012-11-03  
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 22434.txt  
source: https://www.securityfocus.com/bid/7207/info

An information disclosure vulnerability has been reported for Sambar Server. The vulnerability exists in some files existing in Sambar Server's cgi-bin directory.

An attacker can exploit this vulnerability by making a request for these files. This will result in Sambar Server returning potentially sensitive information.

An attacker can use the information obtained in this manner to launch further attacks against a vulnerable host.

http://[target]/cgi-bin/environ.pl
http://[target]/cgi-bin/testcgi.exe