>> Alt-N WebAdmin Multiple Directory Traversal and Privilege Escalation Vulnerabilities
Title : Alt-N WebAdmin Multiple Directory Traversal and Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3333 CVE ID : CVE-2006-4370 - CVE-2006-4371 - CVE-2006-4620
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-21
Technical Description
Multiple vulnerabilities have been identified in Alt-N WebAdmin, which could be exploited by malicious users to disclose sensitive information or obtain elevated privileges.
The first issue is due to input validation errors in the "Logfile_view.wdm" and "configfile_view.wdm" scripts, which could be exploited by global administrators to access and read the contents of arbitrary files on a vulnerable system.
The second issue is due to a design error where a domain administrator can change the global administrator's password and then login with elevated privileges.