[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0364Date: (C)2011-02-18   (M)2023-12-22


The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1025088
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6cee6.shtml
http://www.securityfocus.com/archive/1/516505/100/0/threaded
SECUNIA-43383
SECUNIA-43393
BID-46420
SREASON-8095
SREASON-8197
SREASON-8205
ADV-2011-0424
cisco-security-webagent-file-upload(65436)
http://www.zerodayinitiative.com/advisories/ZDI-11-088

CPE    2
cpe:/a:cisco:security_agent:5.2
cpe:/a:cisco:security_agent:5.1
CWE    1
CWE-94

© SecPod Technologies