vendor:
Intelligent Management Center
by:
Richard Brain of ProCheckUp Ltd
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Intelligent Management Center
Affected Version From: 3.3.9 R2 606 29 Sept 2009
Affected Version To: 3.3 SP1 R2 606 15 Dec 2009
Patch Exists: YES
Related CWE: N/A
CPE: a:3com:intelligent_management_center
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Microsoft SQL 2005
2010
PR10-01: Unauthenticated File Retrieval (traversal) within 3Com* iMC (Intelligent Management Center)
3Com's iMC (Intelligent Management Centre) provides professional management of 3Com and third party network devices, the IMC is normally accessed using a web browser over port 8080.Procheckup has discovered that the IMC management console is vulnerable to a unauthenticated directory traversal attack within the reporting functionality. Directory traversal allows Files to be retrieved from the target server outside the webroot, provided that the location on the file system is known. No authentication is required to exploit this vulnerability.
Mitigation:
Ensure that at least patch 3.3SP2 (R2606P13) has been installed.