As earlier post noted:"The new company Stryon is closely affiliated with The CyberNET Group" and Barton Watson is part of after merger in 6/2002. Stryon seems to have a flaw without a fix reported.
But I don't know computer language or what this is used for that might relate.But here it is.
www.securitytracker.com:
Stryon Instant ASP (iASP) Input Validation Flaw Discloses Files on the System to Remote Users. Read More
http://www.securitytracker.com/alerts/2002/Dec/1005809.htmlCategory: Application (Generic) > iASP Vendors: Stryon
Stryon Instant ASP (iASP) Input Validation Flaw Discloses Files on the System to Remote Users
SecurityTracker Alert ID: 1005809
CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
Date: Dec 13 2002
Impact: Disclosure of system information, Disclosure of user information
Exploit Included: Yes
Version(s): 1.0.9 and prior versions
Description: A file disclosure vulnerability was reported in Stryon's Instant ASP (iASP) in the Remote Console Applet. A remote user can view arbitrary files on the system.
Fate Research Laboratories reported that a remote user can connect to the applet on port 9095 and supply a URL containing '../' directory traversal characters to obtain files on the system.
A demonstration exploit URL is provided:
http://<hostname>:9095/../../../../../../etc/passwdThe vendor has reportedly been notified.
Impact: A remote user can obtain files from the target user's server while the applet is running.
Solution: No solution was available at the time of this entry.
Vendor URL: www.stryon.com/products.asp?s=1 (Links to External Site)
Cause: Access control error, Input validation error
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
Reported By: "ph33r" <ph33r@fatelabs.com>