[ advisories | exploits | discussions | news | conventions | security tools | texts & papers ]
 main menu
- feedback
- advertising
- privacy
- FightAIDS
- newsletter
- news
 
 discussions
- read forum
- new topic
- search
 

 meetings
- meetings list
- recent additions
- add your info
 
 top 100 sites
- visit top sites
- sign up now
- members
 
 webmasters

- add your url
- add domain
- search box
- link to us

 
 projects
- our projects
- free email
 
 m4d network
- security software
- secureroot
- m4d.com
Home : Advisories : BroadVision One-to-One Enterprise Path Disclosure Vulnerability

Title: BroadVision One-to-One Enterprise Path Disclosure Vulnerability
Released by: benjurry
Date: 8th December 2000
Printable version: Click here
1.Description 

    BroadVision One-To-One Enterprise are architected from the ground up using open industry

standards, are inherently distributable, and easily tailored to fit unique business needs. The key

benefits of Java technologies -- ease of programming, interoperability and connectivity -- are core to

BroadVision’s product philosophy.There are many webs using this software include GE Supply.



2.Problem:

    BroadVision One-To-One Enterprise  contains a vulnerability which reveals server information  .

Requesting a non-existent file,the server will reveal the physical path of server files as following:

"Script /appl/bv1to1/bv1to1_var/script-root/login/benjurry.jsp failed, reason unknown "



3.Platforms:

BroadVision One-To-One Enterprise (Maybe all vesions)



4.Exploit

    http://target/benjurry.jsp

Script /appl/bv1to1/bv1to1_var/script-root/login/benjurry.jsp failed, reason unknown 



5.About us

    RAF Info-Tech Corporation Ltd. is an Internet security consulting and service provider. The headquarter of RAF is located in Shenzhen, which is an exciting city in southen of China. For keeping the company  at the leading age of the technology, RAF established an Internet security research center in Tsinghua University in Beijing.

Based on the "RAF Security Theory", the company currently can provide the customized Inernert  security solution to the various clients. RAF also provides the technical services and support to the Internet security  product manufacturers.  



If you are interesting in the RAF's services or having any question to the 



company, please e_mail to chinaraf@public.szptt.net or benjurry@263.net








(C) 1999-2000 All rights reserved.