PT-2015-7231 · Cisco · Cisco Emergency Responder

Publicado

2015-12-13

·

Atualizado

2016-12-07

·

CVE-2015-6406

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Emergency Responder version 10.5(1.10000.5)
Description A directory traversal issue exists in the Tools menu, allowing remote authenticated users to write to arbitrary files by using a crafted filename.
Recommendations For Cisco Emergency Responder version 10.5(1.10000.5), update to a version that fixes this issue, as the current version allows remote authenticated users to write to arbitrary files via a crafted filename.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6406

Produtos afetados

Cisco Emergency Responder