PT-2006-5653 · Ca · Ca Etrust Security Command Center

Published

2006-09-22

·

Updated

2021-04-09

·

CVE-2006-4900

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions CA eTrust Security Command Center versions 1.0 and r8 up to SP1 CR2
Description A directory traversal issue allows remote authenticated users to read and delete arbitrary files by using ".." sequences in the eSCCAdHocHtmlFile parameter to the "eSMPAuditServlet" endpoint. This is due to improper handling by the getadhochtml function.
Recommendations For CA eTrust Security Command Center versions 1.0 and r8 up to SP1 CR2, consider restricting access to the eSMPAuditServlet endpoint until a proper fix is available. As a temporary workaround, avoid using the eSCCAdHocHtmlFile parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4900

Affected Products

Ca Etrust Security Command Center