PT-2009-1998 · Tmaxsoft · Tmaxsoft Jeus
Simon Ryeo
·
Published
2009-03-26
·
Updated
2018-10-11
·
CVE-2008-6528
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TmaxSoft JEUS 5 versions prior to Fix 26
Description
The issue allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream. This is achieved by exploiting the ability to access alternate data streams, specifically by appending
::$DATA to the URL of a script.Recommendations
For TmaxSoft JEUS 5 versions prior to Fix 26, apply Fix 26 to resolve the issue. As a temporary workaround, consider restricting access to sensitive scripts and directories to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tmaxsoft Jeus