5
CVSSv2

CVE-2002-0160

Published: 22/04/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and previous versions and 3.x up to and including 3.01 (build 40), allows remote malicious users to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure access control server 2.6.2

cisco secure access control server 2.6.3

cisco secure access control server 2.6.4

cisco secure access control server 2.6

cisco secure access control server 3.0

cisco secure access control server 3.0.1

Vendor Advisories

Cisco Secure Access Control Server (ACS) for Windows contains two vulnerabilities One vulnerability can lead to the execution of an arbitrary code on an ACS server, and the second can lead to an unauthorized disclosure of information A patch is available for both vulnerabilities Cisco Secure ACS for Unix is not vulnerable No other Cis ...