CVE-2013-3406

The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCug65687.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:service_portal:9.4.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:53

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3406 - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3406 - Vendor Advisory
References () http://tools.cisco.com/security/center/viewAlert.x?alertId=31775 - Vendor Advisory () http://tools.cisco.com/security/center/viewAlert.x?alertId=31775 - Vendor Advisory

Information

Published : 2013-11-18 03:55

Updated : 2024-11-21 01:53


NVD link : CVE-2013-3406

Mitre link : CVE-2013-3406

CVE.ORG link : CVE-2013-3406


JSON object : View

Products Affected

cisco

  • service_portal
CWE
CWE-20

Improper Input Validation