.:[ packet storm ]:.
                           
ignorance isn't always an option
ignorance isn't always an option

 ///  File Name:ZDI-08-076.txt
Description:
A vulnerability allows remote attackers to retrieve arbitrary files on systems with vulnerable installations of EMC Control Center SAN Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists in the SAN Manager Master Agent service (msragent.exe) which listens by default on TCP port 10444. While processing SST_SENDFILE requests the service does not validate the requestor allowing any remote attacker to download arbitrary files.
Homepage:http://www.zerodayinitiative.com/
File Size:3322
Last Modified:Nov 20 18:26:11 2008
MD5 Checksum:674545c3d3f0885dd630ad4bf3b66bd8

 .:. Back