vendor:
At Ease
by:
SecurityFocus
7.5
CVSS
HIGH
At Ease 5.0 Access Control Vulnerability
N/A
CWE
Product Name: At Ease
Affected Version From: 5
Affected Version To: 5.0.2
Patch Exists: YES
Related CWE: N/A
CPE: o:apple:at_ease
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MacOS 7.6.1, AppleShare IP 5.0.3, Netscape 4.0.7
1998
At Ease 5.0 Access Control Vulnerability
At Ease 5.0 is vulnerable to an access control vulnerability that allows a user to access any user's volume on the server through a web browser. By logging in as any user that has access to Netscape Communicator and typing in the file path, it is possible to browse through any user's files and download them.
Mitigation:
Upgrade to a version of At Ease 5.0 that is not vulnerable.