Shareplex Arbitary Local File...

- AV AC AU C I A
发布: 2001-03-30
修订: 2025-04-13

Shareplex is a database replication tool from Quest Software. Versions of the product contain a vulnerability which can permit local unprivileged users to read arbitrary files. The Qview component of Shareplex allows its user to specify a file containing Qview commands as input. If the contents of the file are not valid Qview commands, they will be output to standard error as part of error messages. Exploiting this behaviour, an attacker can obtain the contents of normally unreadable, sensitive files from this error output. This may lead to a compromise of enhanced privileges.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息