Full Disclosure mailing list archives
DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability
From: "DDI_Vulnerability_Alert" <DDI.VulnerabilityAlert () ddifrontline com>
Date: Mon, 9 Mar 2009 09:36:23 -0500
Title ----- DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability Severity -------- High Date Discovered --------------- January 19th, 2009 Discovered By ------------- Digital Defense, Inc. Vulnerability Research Team Credit: David Marshall and r@b13$ Vulnerability Description ------------------------- A directory traversal condition exists in SMART Web Server whereby arbitrary files may be retrieved from this host's file system. Attackers may leverage this issue to gain access to sensitive information stored on this host. Solution Description -------------------- No patch is available at this time. Tested Systems / Software (with versions) ------------------------------------------ Windows XP, SMART Board Whiteboard Vendor Contact -------------- Vendor Name: SMART Technologies ULC Vendor Website: http://www2.smarttech.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability DDI_Vulnerability_Alert (Mar 09)