Cisco Enterprise Content Delivery System (ECDS) CVE-2014-8019 Arbitrary File Access Vulnerability
BID:71764
Info
Cisco Enterprise Content Delivery System (ECDS) CVE-2014-8019 Arbitrary File Access Vulnerability
| Bugtraq ID: | 71764 |
| Class: | Unknown |
| CVE: |
CVE-2014-8019 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2014 12:00AM |
| Updated: | Dec 24 2014 12:58AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Enterprise Content Delivery System (ECDS) CVE-2014-8019 Arbitrary File Access Vulnerability
Cisco Enterprise Content Delivery System (ECDS) is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to access arbitrary files in the context of the web server process, which may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCuo90148.
Cisco Enterprise Content Delivery System (ECDS) is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to access arbitrary files in the context of the web server process, which may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCuo90148.
Exploit / POC
Cisco Enterprise Content Delivery System (ECDS) CVE-2014-8019 Arbitrary File Access Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Cisco Enterprise Content Delivery System (ECDS) CVE-2014-8019 Arbitrary File Access Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Enterprise Content Delivery System (ECDS) CVE-2014-8019 Arbitrary File Access Vulnerability
References:
References:
- Cisco Homepage (Cisco)