TUCoPS :: Windows Apps :: quotaadv.htm

QuotaAdvisor 4.1 - list all files on a server running this
Vulnerability

    QuotaAdvisor

Affected

    QuotaAdvisor 4.1 (Build 450) by WQuinn

Description

    Following  is  based  on  a  Delphis  Consulting Security Advisory
    DST2K0040.   Delphis  Consulting  Internet  Security  Team (DCIST)
    discovered  the  following  vulnerability  in  WQuinn QuotaAdvisor
    under WindowsNT.

    It is possible to list all of the files contained on a file system
    which is  on a  server with  QuotaAdvisor running  upon it.   This
    requires    only    a    normal    user    account    (i.e.    non
    adminstrator/poweruser).   This normal  user account  can list the
    top level administration shares but not the contents.  However  if
    you  run  a  report  upon  that  share  the  report will contain a
    complete list of files and their physical locations.

Solution

    Nothing yet.

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH