consoleConnect.jsp in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to connect to arbitrary consoles by modifying the consolename parameter.Referenceshttp://secunia.com/advisories/14378http://marc.info/?l=full-disclosure&m=110924450827137&w=2http://www.cirt.net/advisories/alterpath_console.shtmlhttp://www.osvdb.org/14075