[Forgot Password]
Login  Register Subscribe

23631

 
 

122183

 
 

98060

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-1432

Date: (C)2009-04-30   (M)2017-08-18 


Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.

CVSS Score: 5.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: PARTIAL
 Availability: NONE





Reference:
SECTRACK-1022136
SECTRACK-1022137
SECTRACK-1022138
BID-34668
SECUNIA-34856
SECUNIA-34935
ADV-2009-1202
ADV-2009-1204
IAVM:2009-A-0037
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00
multiple-symantec-login-spoofing(50172)

CPE    16
cpe:/a:symantec:antivirus_central_quarantine_server
cpe:/a:symantec:client_security:3.0.2.2010
cpe:/a:symantec:client_security:3.0.2.2011
cpe:/a:symantec:client_security:3.0.1.1000
...
CWE    1
CWE-20
OVAL    1
oval:org.secpod.oval:def:9758

© 2013 SecPod Technologies