J-Security Center

Title: Air Messenger LAN Server Path Disclosure Vulnerability

Severity: HIGH

Description:

Air Messenger LAN Server for Microsoft Windows allows users to exchange phone, pager and email messages through a Web gateway.

The path to sensitive files used by AMLServer can be easily obtained by any remote user, simply by examining the webserver's http-header 'Location' field.

Properly exploited, this information could assist an attacker in obtaining AMLServer username and password information (stored in plaintext, see BIDS 2882 and 2883).

This in turn could have a range of undesirable effects, including granting an attacker access to AMLServer's messages and services, or assisting in a denial of service attack on the affected system.

Affected Products:

  • Internet Software Solutions Air Messenger LAN Server 3.4.2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.