[24801] in bugtraq
Webtraversal in PCI Netsupport Manager (all version up to 7 using
daemon@ATHENA.MIT.EDU (watcher60@hotmail.com)
Fri Mar 22 17:02:21 2002
Date: 22 Mar 2002 00:40:06 -0000
Message-ID: <20020322004006.7089.qmail@mail.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <watcher60@hotmail.com>
To: bugtraq@securityfocus.com
It is possible to view and download files on machines
running PCI Netsupport Manager (all version up to 7)
that have the web extensions switched on (default
port 80). This has only been tested on Windows NT 4
(server and workstation) and Windows 2000 (Pro ,
Server and Advanced server).
Example on a standard version 5.5 install (location
c:\nsm) the URL to view the boot.ini file in the root
would be:
http://machinename:relevant_port/../boot.ini
version 6 +:
http://machinename:relevant_port/../../boot.ini
I have received confirmation from PCI that this bug is
fixed in version 7 onwards
Watcher60