newsbot
19-03-2008, 03:07 PM
Client Management Services (http://www.argontechnology.com/product.aspx/cid1/43) (CMS) includes "all the server-based services (PXE Server, BOOTP Server) and administration tools needed to setup an open network boot environment. You can deploy your favorite third party client management tools in a pre-OS booting phase." The Argon Client Management Services TFTP Boot Server is affected by a classical directory traversal vulnerability which allows an attacker to download (upload is not allowed) any file from the disk where is located the tftp folder.
http://www.securiteam.com/windowsntfocus/5OP0F2KNPU.html
http://www.securiteam.com/windowsntfocus/5OP0F2KNPU.html