Описание
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-6435
- https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunking
- https://www.exploit-db.com/exploits/40464
- https://www.korelogic.com/Resources/Advisories/KL-001-2016-006.txt
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc2
- http://www.securityfocus.com/bid/93421
Связанные уязвимости
CVSS3: 6.5
nvd
больше 9 лет назад
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.