CVE-2013-2068 - CERT CVE
ID CVE-2013-2068
Sažetak Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.
Reference
CVSS
Base: 9.4
Impact: 9.2
Exploitability:10.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE COMPLETE COMPLETE
CVSS vektor AV:N/AC:L/Au:N/C:N/I:C/A:C
Zadnje važnije ažuriranje 14-01-2014 - 04:24
Objavljeno 28-09-2013 - 19:55