Vulnerabilities > CVE-2006-4899 - Unspecified vulnerability in Broadcom Etrust Security Command Center 1.0/8

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
broadcom
exploit available

Summary

The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message.

Vulnerable Configurations

Part Description Count
Application
Broadcom
4

Exploit-Db

descriptionCA eSCC r8/1.0,eTrust Audit r8/1.5 Web Server Path Disclosure. CVE-2006-4899. Remote exploit for windows platform
idEDB-ID:28640
last seen2016-02-03
modified2006-09-21
published2006-09-21
reporterPatrick Webster
sourcehttps://www.exploit-db.com/download/28640/
titleCA eSCC r8/1.0,eTrust Audit r8/1.5 Web Server Path Disclosure