10

CVE-2011-1566

Exploit
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17 to TCP port 12397.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
7tIgss
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 66.98% 0.992
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://secunia.com/advisories/43849
Vendor Advisory
http://www.exploit-db.com/exploits/17024
Exploit
http://www.securityfocus.com/bid/46936
Exploit
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-03.pdf
US Government Resource
http://www.vupen.com/english/advisories/2011/0741
Vendor Advisory
http://aluigi.org/adv/igss_8-adv.txt