The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote malicious users to obtain sensitive information in conjunction with a directory traversal (..) attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sun sunos 5.8 |
||
sun solaris 9.0 |
||
sun solaris 8.0 |