Back to search
CVE-2006-4899
Published: Sep 22, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ca-etrust-eppiservlet-path-disclosure(29102)
vdb-entry
x_refsource_XF
29009
vdb-entry
x_refsource_OSVDB
1016910
vdb-entry
x_refsource_SECTRACK
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34616
x_refsource_CONFIRM
22023
third-party-advisory
x_refsource_SECUNIA
20139
vdb-entry
x_refsource_BID
20060922 RE: Computer Associates eTrust Security Command Center Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
20060921 [CAID 34616, 34617, 34618]: CA eSCC and eTrust Audit vulnerabilities
mailing-list
x_refsource_BUGTRAQ
ADV-2006-3738
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now