[21307] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Nfuse reveals full path

daemon@ATHENA.MIT.EDU (rjmitchell@nisource.com)
Mon Jul 2 16:34:35 2001

From: rjmitchell@nisource.com
To: "        -         *bugtraq@securityfocus.com" <bugtraq@securityfocus.com>
Message-ID: <0056990021554913000002L932*@MHS>
Date: Mon, 2 Jul 2001 07:15:31 -0400
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

Greetings,

What version of NFuse are you running? I tested this with version 1.51 and here
is the error I saw:

There was an error:
This operation requires user credentials to be specified. The following session
field was not set: NFUSE_USER

As you can see, no revealing of the path.

Regards,

- Rick Mitchell
Systems Engineer
Columbia Gas Transmission





sween@modelm.org on 07/02/2001 06:19:51 AM
Please respond to sween@modelm.org


To: bugtraq@securityfocus.com
cc:

Subject: Nfuse reveals full path




I googled for a bit, and didn't find it after I stumbled upon it.
/me apologizes if this is common knowledge

http://pooter/nfuse/asp/launch.asp?


Produces:

There was an error:
The Citrix HTML template contains tags that require an app to be specified
via the NFuse_Application session field, but this session field was not
set.

The template with the error is located at

D:\Inetpub\wwwroot\nfuse\asp\template.ica



--

 ---  -sween
| M | http://www.modelm.org
 ---  "force feedback computing since 1984."





home help back first fref pref prev next nref lref last post