Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.801852
Kategorie:Web application abuses
Titel:F-Secure Policy Manager 'WebReporting' Module XSS And Path Disclosure Vulnerabilities
Zusammenfassung:This host is running F-Secure Policy Manager and is prone to cross; site scripting and path disclosure vulnerabilities.
Beschreibung:Summary:
This host is running F-Secure Policy Manager and is prone to cross
site scripting and path disclosure vulnerabilities.

Vulnerability Insight:
The flaws are caused by an error in the 'WebReporting' interface when
processing user-supplied requests, which could allow cross-site scripting
and path disclosure attacks.

Vulnerability Impact:
Successful exploitation will allow attacker to disclose potentially sensitive
information and execute arbitrary code in the context of an application.

Affected Software/OS:
F-Secure Policy Manager versions 7.x, 8.x and 9.x

Solution:
Apply the patch for installed version from the referenced links.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: BugTraq ID: 46547
Common Vulnerability Exposure (CVE) ID: CVE-2011-1102
http://www.securityfocus.com/bid/46547
http://www.securitytracker.com/id?1025124
http://secunia.com/advisories/43049
http://www.vupen.com/english/advisories/2011/0509
XForce ISS Database: fsecure-webreporting-xss(65665)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65665
Common Vulnerability Exposure (CVE) ID: CVE-2011-1103
XForce ISS Database: fsecure-webreporting-path-disclosure(65664)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65664
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.