Back to search
CVE-2006-4900
Published: Sep 22, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1016910
vdb-entry
x_refsource_SECTRACK
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34617
x_refsource_CONFIRM
22023
third-party-advisory
x_refsource_SECUNIA
29010
vdb-entry
x_refsource_OSVDB
ca-etrust-esmpauditservlet-dir-traversal(29104)
vdb-entry
x_refsource_XF
20139
vdb-entry
x_refsource_BID
20060922 RE: Computer Associates eTrust Security Command Center Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
20060921 [CAID 34616, 34617, 34618]: CA eSCC and eTrust Audit vulnerabilities
mailing-list
x_refsource_BUGTRAQ
ADV-2006-3738
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now