[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

HIS Command Execution Vulnerability

ID: oval:org.mitre.oval:def:6075Date: (C)2008-10-14   (M)2022-10-10
Class: VULNERABILITYFamily: windows




Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."

Platform:
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Product:
Microsoft Host Integration Server 2000
Microsoft Host Integration Server 2004 Client
Microsoft Host Integration Server 2004
Microsoft Host Integration Server 2006
Reference:
CVE-2008-3466
CVE    1
CVE-2008-3466
CPE    6
cpe:/a:microsoft:host_integration_server_client:2004:-
cpe:/a:microsoft:host_intergration_server:2004:SP1
cpe:/a:microsoft:host_intergration_server:2004
cpe:/a:microsoft:host_integration_server_client:2004:sp1
...

© SecPod Technologies