HTTP: F-Secure Policy Manager information disclosure

This signature detects attempts to obtain information about an F-Secure Policy Manager installation. The web server managing the policy allows unauthenticated users to retrieve information about the software installation.

Extended Description

F-Secure Policy Manager includes a CGI application named 'fsmsh.dll'. By supplying unexpected input as an argument to the 'fsmsh.dll' application the vulnerable software will return an error message that includes the installation path of the software.

Affected Products

F-secure policy_manager

Short Name
HTTP:INFO-LEAK:F-SECURE-MANAGER
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2004-1223 F-Secure Manager Policy bid:11869 disclosure information
Release Date
03/10/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

F-secure

CVSS Score

5.0

Found a potential security threat?