CVE-2006-4899
Summary
| CVE | CVE-2006-4899 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-22 22:07:00 UTC |
| Updated | 2021-04-09 16:21:00 UTC |
| Description | The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Broadcom | Etrust Security Command Center | 1.0 | All | All | All |
| Application | Broadcom | Etrust Security Command Center | 8 | All | All | All |
| Application | Broadcom | Etrust Security Command Center | 8 | sp1 | cr1 | All |
| Application | Broadcom | Etrust Security Command Center | 8 | sp1 | cr2 | All |
| Application | Ca | Etrust Security Command Center | 1.0 | All | All | All |
| Application | Ca | Etrust Security Command Center | 8 | All | All | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr1 | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr2 | All |
| Application | Ca | Etrust Security Command Center | 1.0 | All | All | All |
| Application | Ca | Etrust Security Command Center | 8 | All | All | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr1 | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr2 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | MISC | users.tpg.com.au | Exploit, Patch, Vendor Advisory |
| CA eTrust Security Command Center and eTrust Audit Multiple Vulnerabilities | BID | www.securityfocus.com | |
| CA eTrust Security Command Center reveal web server path vulnerability - CA | CONFIRM | www3.ca.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CA eTrust Security Command Center Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Exploit, Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - CA eTrust Security Command Center Lets Remote Authenticated Users Read/Delete Files and Lets Remote Users Conduct Replay Attacks | SECTRACK | securitytracker.com | |
| 29009 | OSVDB | www.osvdb.org | |
| IT Management software and solutions from CA | CONFIRM | www3.ca.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.