OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: BroadVision One-To-One Enterprise Path Disclosure Vulnerability
From: benjurry (benjurryYEAH.NET)
Date: Thu Dec 07 2000 - 21:07:06 CST


1.Description
    BroadVision One-To-One Enterprise are architected from the ground up using open industry
standards, are inherently distributable, and easily tailored to fit unique business needs. The key
benefits of Java technologies -- ease of programming, interoperability and connectivity -- are core to
BroadVisionĄ¯s product philosophy.There are many webs using this software include GE Supply.

2.Problem:
    BroadVision One-To-One Enterprise contains a vulnerability which reveals server information .
Requesting a non-existent file,the server will reveal the physical path of server files as following:
"Script /appl/bv1to1/bv1to1_var/script-root/login/benjurry.jsp failed, reason unknown "

3.Platforms:
BroadVision One-To-One Enterprise (Maybe all vesions)

4.Exploit
    http://target/benjurry.jsp
Script /appl/bv1to1/bv1to1_var/script-root/login/benjurry.jsp failed, reason unknown

5.About us
    RAF Info-Tech Corporation Ltd. is an Internet security consulting and service provider. The headquarter of RAF is located in Shenzhen, which is an exciting city in southen of China. For keeping the company at the leading age of the technology, RAF established an Internet security research center in Tsinghua University in Beijing.
Based on the "RAF Security Theory", the company currently can provide the customized Inernert security solution to the various clients. RAF also provides the technical services and support to the Internet security product manufacturers.

If you are interesting in the RAF's services or having any question to the

company, please e_mail to chinarafpublic.szptt.net or benjurry263.net