Vulnerability CVE-2006-0993


Published: 2006-05-09   Modified: 2012-02-12

Description:
The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might allow remote attackers to obtain potentially sensitive information such as configuration settings.

See advisories in our WLB2 database:
Topic
Author
Date
Low
3Com TippingPoint SMS Server Information Disclosure Vulnerability
zdi-disclosures ...
12.05.2006

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
3COM -> Tippingpoint sms server 

 References:
http://securityreason.com/securityalert/870
http://securitytracker.com/id?1016051
http://www.3com.com/securityalert/alerts/3COM-06-002.html
http://www.securityfocus.com/archive/1/433432/100/0/threaded
http://www.securityfocus.com/bid/17935
http://www.vupen.com/english/advisories/2006/1752
http://www.zerodayinitiative.com/advisories/ZDI-06-013.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/26338

Copyright 2024, cxsecurity.com

 

Back to Top