6.8
CVSSv2

CVE-2011-0966

Published: 20/05/2011 Updated: 14/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 690
Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ciscoworks common services 2.2

cisco ciscoworks common services

cisco ciscoworks common services 3.0.6

cisco ciscoworks common services 3.0.4

cisco ciscoworks common services 3.2

cisco ciscoworks common services 1.0

cisco ciscoworks common services 3.1.1

cisco ciscoworks common services 3.0

cisco ciscoworks common services 3.1

cisco ciscoworks common services 3.0.3

cisco ciscoworks common services 3.0.5

Exploits

Cisco Unified Operations Manager suffers from cross site scripting, remote SQL injection, and directory traversal vulnerabilities Versions 80 and 85 are affected ...
source: wwwsecurityfocuscom/bid/47905/info CiscoWorks Common Services is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input A remote attacker could exploit this vulnerability using directory-traversal strings (such as '/') to gain access to arbitrary files on the targeted system ...
Sense of Security - Security Advisory - SOS-11-006 Release Date 18-May-2011 Last Update - Vendor Notification Date 28-Feb-2011 Product Cisco Unified Operations Manager Common Services Framework Help Servlet Common Service ...