vendor:
Asset Manager v6.6
by:
Unknown
5.5
CVSS
MEDIUM
Unauthenticated arbitrary file read, Authenticated SQL injection
Unknown
CWE
Product Name: Asset Manager v6.6
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
McAfee Asset Manager v6.6 multiple vulnerabilities
An unprivileged authenticated user can download arbitrary files with the permissions of the web server using the report download functionality. By generating a report, the user's browser will make a request to /servlet/downloadReport?reportFileName=blah. The user can put in a relative directory traversal attack and download /etc/passwd. An unprivileged authenticated user can initiate a SQL injection attack by creating an audit report and controlling the username specified in the audit report.
Mitigation:
Unknown