CVE-2006-4900
Summary
| CVE | CVE-2006-4900 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-22 22:07:00 UTC |
| Updated | 2021-04-09 16:21:00 UTC |
| Description | Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Broadcom | Etrust Security Command Center | 8 | All | All | All |
| Application | Broadcom | Etrust Security Command Center | 8 | sp1 | cr1 | All |
| Application | Broadcom | Etrust Security Command Center | 8 | sp1 | cr2 | All |
| Application | Ca | Etrust Security Command Center | 8 | All | All | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr1 | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr2 | All |
| Application | Ca | Etrust Security Command Center | 8 | All | All | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr1 | All |
| Application | Ca | Etrust Security Command Center | 8 | sp1 | cr2 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | MISC | users.tpg.com.au | Exploit, Patch, Vendor Advisory |
| CA eTrust Security Command Center and eTrust Audit Multiple Vulnerabilities | BID | www.securityfocus.com | |
| 29010 | OSVDB | www.osvdb.org | Exploit, Patch |
| CA eTrust Security Command Center read and delete arbitrary files vulnerability | CONFIRM | www3.ca.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CA eTrust Security Command Center Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Exploit, Patch, Vendor Advisory |
| SecurityTracker.com Archives - CA eTrust Security Command Center Lets Remote Authenticated Users Read/Delete Files and Lets Remote Users Conduct Replay Attacks | SECTRACK | securitytracker.com | |
| IT Management software and solutions from CA | CONFIRM | www3.ca.com | Exploit, Patch, Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.