PT-2006-5653 · Ca · Ca Etrust Security Command Center

Publicado

2006-09-22

·

Atualizado

2021-04-09

·

CVE-2006-4900

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions CA eTrust Security Command Center versions 1.0 and r8 up to SP1 CR2
Description A directory traversal issue allows remote authenticated users to read and delete arbitrary files by using ".." sequences in the eSCCAdHocHtmlFile parameter to the "eSMPAuditServlet" endpoint. This is due to improper handling by the getadhochtml function.
Recommendations For CA eTrust Security Command Center versions 1.0 and r8 up to SP1 CR2, consider restricting access to the eSMPAuditServlet endpoint until a proper fix is available. As a temporary workaround, avoid using the eSCCAdHocHtmlFile parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4900

Produtos afetados

Ca Etrust Security Command Center