← Back

CVE-2006-4900

nvd nist
Published: Sep 22, 2006Modified: Apr 16, 2026

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:P
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function.

Affected (3)

1 product
Etrust Security Command Center
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Broadcom
Version 8
Version 8 sp1
Version 8 sp1

References (22)

Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.