[vuln.sg] Vulnerability Research Advisory Cybozu Products Arbitrary File Retrieval Vulnerability by Tan Chew Keong Release Date: 2006-08-28 Summary ------- A vulnerability has been found in Cybozu Products. When exploited, the vulnerability allows an authenticated user to retrieve arbitrary files accessible to the web server process. Tested Versions --------------- Cybuzu Office Version 6.5 (Build 1.2 20050427121735) for Windows Cybozu Share 360 Version 2.5 (Build 0.2 20050121115231) for Windows Details ------- http://vuln.sg/cybozu-en.html http://vuln.sg/cybozu-jp.html _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/