[] NeoSense

M-TECH P-Synch 6.2.5 - Full Path Disclosure

Author: JeiAr
type: remote
platform: windows
port: 
date_added: 2003-05-29 
date_updated: 2012-11-13 
verified: 1 
codes: OSVDB-4919 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/7740/info

Reportedly an attacker may make a malicious HTTP request for specific P-Synch executables passing an empty URI parameter to trigger the condition. Although unconfirmed, it is likely that the request will cause P-Sync to display an error message containing the path to the executable.

This vulnerability was reported to affect P-Synch version 6.2.5 other versions may also be affected.

https://www.example.org/psynch/nph-psa.exe?lang=
https://www.example.org/psynch/nph-psf.exe?lang=