7.5
CVE-2010-0114
- EPSS 5.05%
- Veröffentlicht 22.12.2010 01:00:02
- Zuletzt bearbeitet 16.06.2026 23:15:30
- Erkennungen
fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Endpoint Protection Version 11.0
Symantec ≫ Endpoint Protection Version 11.0 Update ru5
Symantec ≫ Endpoint Protection Version 11.0 Update ru6
Symantec ≫ Endpoint Protection Version 11.0 Update ru6mp1
Symantec ≫ Endpoint Protection Version 11.0.1
Symantec ≫ Endpoint Protection Version 11.0.1 Update mp1
Symantec ≫ Endpoint Protection Version 11.0.2
Symantec ≫ Endpoint Protection Version 11.0.2 Update mp1
Symantec ≫ Endpoint Protection Version 11.0.2 Update mp2
Symantec ≫ Endpoint Protection Version 11.0.4
Symantec ≫ Endpoint Protection Version 11.0.4 Update mp1a
Symantec ≫ Endpoint Protection Version 11.0.4 Update mp2
Symantec ≫ Endpoint Protection Version 11.0.3001
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.05% | 0.912 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/42643
http://securitytracker.com/id?1024900
http://www.securityfocus.com/bid/45372
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20101215_00
http://www.vupen.com/english/advisories/2010/3252
http://www.zerodayinitiative.com/advisories/ZDI-10-291/
https://exchange.xforce.ibmcloud.com/vulnerabilities/64118