about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SonicWALL Global VPN Client Log File Remote Format String Vulnerability


Title SonicWALL Global VPN Client Log File Remote Format String Vulnerability
Published 2009-05-26-12:00AM
Updated 2009-05-26-05:10PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  lofi42 from SEC Consult
Vulnerable  SonicWALL Global VPN Client 4.0 251e Standard
SonicWALL Global VPN Client 4.0 251e Enhanced
Not Vulnerable  
Code  The following proofs of concept are available:1. CFS: Add example.com to your "Forbidden Domains" and access http://www.example.com/%s%s%s%s%s%s/.2. GroupVPN: Establish a GroupVPN Tunnel and enter at the XAUTH Username %s%s%s%s%s.3. Webfrontend: Enter at the Login Page of your SonicWALL as Username %s%s%s%s%s
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 10:00:24 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.lexsen maxcpm.inf www.lexsen ping local news for c Sexo grati /component www.1893d. maxcpm.inf www.wommen counter st Xxxxvedio Tagger LE. Invision ok188.weeb Tagger LE. news for c yangeasy.c phpBB por SEX CHANAL CMS is Fre ok188.weeb ok188.weeb Serv-U FTP www 89 /includes/ www.0372se hayfa wahb Tagger LE. ne olur ev Tagger LE. pnuke chenzhou.1 mega www700 c CMPS www.ok92.c www.gpshy. YABB+2.1 www.cjwend hack0821.c Baker deci ok188.weeb ok188.weeb ok188.weeb news for c crlzwf.cn ok188.weeb vixie cron oensex