CVE-2010-0146
published 2010-02-23CVE-2010-0146: Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via…
PriorityP431medium6.8CVSS 2.0
AVNACLAuSCCINAN
EPSS
2.73%
84.4th percentile
Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w76v-j738-xmxx: Directory traversal vulnerability in the Management Center for Cisco Security Agents 6
ghsa_unreviewed·2022-05-02
CVE-2010-0146 [MEDIUM] CWE-22 GHSA-w76v-j738-xmxx: Directory traversal vulnerability in the Management Center for Cisco Security Agents 6
Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.
Cisco
Multiple Vulnerabilities in Cisco Security Agent
vendor_cisco·2010-02-17·CVSS 9.0
CVE-2010-0146 [CRITICAL] CWE-22 Multiple Vulnerabilities in Cisco Security Agent
Multiple Vulnerabilities in Cisco Security Agent
The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability. Successful exploitation of the directory traversal vulnerability may allow an authenticated attacker to view and download arbitrary files from the server hosting the Management Center. Successful exploitation of the SQL injection vulnerability may allow an authenticated attacker to execute SQL statements that can cause instability of the product or changes in the configuration.
Additionally, the Cisco Security Agent is affected by a denial of service (DoS) vulnerability. Successful exploitation of the Cisco Security Agent agent DoS vulnerability may cause the affected system to crash. Repeated exploitation co
Cisco
Multiple Vulnerabilities in Cisco Security Agent
vendor_cisco
CVE-2010-0146 Multiple Vulnerabilities in Cisco Security Agent
CVE-2010-0146: Multiple Vulnerabilities in Cisco Security Agent
The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability. Successful exploitation of the directory traversal vulnerability may allow an authenticated attacker to view and download arbitrary files from the server hosting the Management Center. Successful exploitation of the SQL injection vulnerability may allow an authenticated attacker to execute SQL statements that can cause instability of the product or changes in the configuration. Additionally, the Cisco Security Agent is affected by a denial of service (DoS) vulnerability. Successful exploitation of the Cisco Security Agent agent DoS vulnerability may cause the affected system to crash. Repeated e
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/62443http://secunia.com/advisories/38619http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtmlhttp://www.securityfocus.com/bid/38271http://www.securitytracker.com/id?1023606http://www.vupen.com/english/advisories/2010/0416https://exchange.xforce.ibmcloud.com/vulnerabilities/56345http://osvdb.org/62443http://secunia.com/advisories/38619http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtmlhttp://www.securityfocus.com/bid/38271http://www.securitytracker.com/id?1023606http://www.vupen.com/english/advisories/2010/0416https://exchange.xforce.ibmcloud.com/vulnerabilities/56345
2010-02-23
Published