Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1036

Опубликовано: 25 фев. 2011
Источник: nvd
CVSS2: 8.8
EPSS Низкий

Описание

The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:ca:host-based_intrusion_prevention_system:8.1:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:ca:internet_security_suite_2010:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:internet_security_suite_2011:*:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05056
Низкий

8.8 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods.

EPSS

Процентиль: 90%
0.05056
Низкий

8.8 High

CVSS2

Дефекты

NVD-CWE-Other