![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.804513 |
Categoría: | Web application abuses |
Título: | Symantec Endpoint Protection Manager XXE and SQL Injection Vulnerabilities |
Resumen: | Symantec Endpoint Protection Manager is prone to XXE and SQL injection vulnerabilities. |
Descripción: | Summary: Symantec Endpoint Protection Manager is prone to XXE and SQL injection vulnerabilities. Vulnerability Insight: Flaw is due to an error when handling XML data within the servlet/ConsoleServlet. Vulnerability Impact: Successful exploitation will allow attackers to disclose potentially sensitive information, manipulate certain data, and cause a DoS (Denial of Service). Affected Software/OS: Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080 Solution: Upgrade Symantec Endpoint Protection Manager to version 11.0.7405.1424 or 12.1.4023.4080 or later, and Symantec Protection Center Small Business Edition to version 12.1.4023.4080 or later. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-5014 BugTraq ID: 65466 http://www.securityfocus.com/bid/65466 http://www.exploit-db.com/exploits/31853 http://www.exploit-db.com/exploits/31917 https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140218-0_Symantec_Endpoint_Protection_Multiple_critical_vulnerabilities_wo_poc_v10.txt Common Vulnerability Exposure (CVE) ID: CVE-2013-5015 BugTraq ID: 65467 http://www.securityfocus.com/bid/65467 http://osvdb.org/103306 |
Copyright | Copyright (C) 2014 Greenbone AG |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |