| |
Vulnerability CVE-2013-3398
Published: 2013-06-26 Modified: 2013-06-27
Description: |
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pathnames depending on whether the pathname exists, which allows remote attackers to enumerate directories and files via a series of crafted requests, aka Bug ID CSCuh64574. |
Type:
CWE-200 (Information Exposure)
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5/10 |
2.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3398
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|