VP-2014-004 SysAid Server Arbitrary File Disclosure

Posted by Vantage Point Security on Dec 22

Vantage Point Security Advisory 2014-004
========================================

Title: SysAid Server Arbitrary File Disclosure
ID: VP-2014-004
Vendor: SysAid
Affected Product: SysAid On-Premise
Affected Versions: < 14.4.2
Product Website: http://www.sysaid.com/product/sysaid
Author: Bernhard Mueller <bernhard[at]vantagepoint[dot]sg>

Summary:

SysAid Server is vulnerable to an unauthenticated file disclosure
attack that allows an…

Leave a Reply