Vulnerabilities > CVE-2006-4900 - Unspecified vulnerability in Broadcom Etrust Security Command Center 8

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
broadcom
exploit available

Summary

Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function.

Vulnerable Configurations

Part Description Count
Application
Broadcom
3

Exploit-Db

descriptionCA eSCC r8/1.0,eTrust Audit r8/1.5 Unspecified Arbitrary File Manipulation. CVE-2006-4900. Remote exploit for windows platform
idEDB-ID:28641
last seen2016-02-03
modified2006-09-21
published2006-09-21
reporterPatrick Webster
sourcehttps://www.exploit-db.com/download/28641/
titleCA eSCC r8/1.0,eTrust Audit r8/1.5 Unspecified Arbitrary File Manipulation