Cisco Security Agent Management Center Directory Traversal Vulnerability
BID:38271
Info
Cisco Security Agent Management Center Directory Traversal Vulnerability
| Bugtraq ID: | 38271 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0146 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2010 12:00AM |
| Updated: | Feb 17 2010 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Security Agent 6.0 |
| Not Vulnerable: |
Cisco Security Agent 6.0.1.132 |
Discussion
Cisco Security Agent Management Center Directory Traversal Vulnerability
Cisco Security Agent is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to download arbitrary files from the server that is hosting the Management Center for Cisco Security Agents.
This issue is tracked by Cisco BugID CSCtd73275.
Cisco Security Agent is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to download arbitrary files from the server that is hosting the Management Center for Cisco Security Agents.
This issue is tracked by Cisco BugID CSCtd73275.
Exploit / POC
Cisco Security Agent Management Center Directory Traversal Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Cisco Security Agent Management Center Directory Traversal Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Cisco Security Agent Management Center Directory Traversal Vulnerability
References:
References: