CVE-2006-3426
Summary
| CVE | CVE-2006-3426 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-07 00:05:00 UTC |
| Updated | 2018-10-18 16:47:00 UTC |
| Description | Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lumension | Patchlink Update Server | 6.1 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.181 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.189 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.1 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.181 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.189 | All | All | All |
| Application | Novell | Zenworks | All | sr1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PatchLink Update Bugs Let Remote Users Inject SQL Commands, Modify the Configuration, and Create or Overwrite Files - SecurityTracker | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CXSecurity - IDS | SREASON | securityreason.com | |
| PatchLink Update Server Arbitrary File Overwrite Vulnerability | BID | www.securityfocus.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| [Full-disclosure] Multiple Vulnerabilities in PatchLink Update Server 6 | FULLDISC | lists.grok.org.uk | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Secunia - Advisories - Novell ZENworks Patch Management Multiple Vulnerabilities | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.