Cisco Content Service Switch FTP Access Control Vulnerability
BID:2745
Info
Cisco Content Service Switch FTP Access Control Vulnerability
| Bugtraq ID: | 2745 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2001 12:00AM |
| Updated: | May 17 2001 12:00AM |
| Credit: | This vulnerability was announced to Bugtraq in a Cisco Security Advisory on May 18, 2001. |
| Vulnerable: |
Cisco WebNS 4.0.1 B19s Cisco WebNS 4.0.1 Cisco WebNS 4.0 |
| Not Vulnerable: |
Cisco WebNS 4.1 0B13s Cisco WebNS 4.0 1B23s |
Discussion
Cisco Content Service Switch FTP Access Control Vulnerability
The Cisco Content Service (CSS) switch is an Enterprise-level utility by Cisco Systems. The CSS switch is a Layer 5 and 7 aware switch capable of providing a high performance frontend to web server farms and caches.
A problem with the switch could allow non-privileged users to upload files to the switch. The switch allows any user with a valid account to use the FTP PUT and GET functions.
This problem makes it possible for a remote user to overwrite local files, or gain access to sensitive files.
The Cisco Content Service (CSS) switch is an Enterprise-level utility by Cisco Systems. The CSS switch is a Layer 5 and 7 aware switch capable of providing a high performance frontend to web server farms and caches.
A problem with the switch could allow non-privileged users to upload files to the switch. The switch allows any user with a valid account to use the FTP PUT and GET functions.
This problem makes it possible for a remote user to overwrite local files, or gain access to sensitive files.
Exploit / POC
Cisco Content Service Switch FTP Access Control Vulnerability
See discussion.
See discussion.
References
Cisco Content Service Switch FTP Access Control Vulnerability
References:
References:
- Cisco Content Service Switch 11000 Series FTP Vulnerability (Cisco Systems)