Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-1182 | First vendor Publication | 2006-03-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:H/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.6 | Attack Range | Local |
Cvss Impact Score | 4.9 | Attack Complexity | High |
Cvss Expoit Score | 1.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1182 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 | |
Application | 2 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
23924 | Adobe Document/Graphics Server File URI Arbitrary Resource Manipulation Adobe Document/Graphics Server contain a flaw that may lead to an unauthorized information disclosure, an arbitrary file overwrite, or a compromised system. The issue is caused due to the 'loadContent', 'saveContent', and 'saveOptimized' ADS (Adobe Document Server) commands allowing graphics or PDF files to be retrieved from or saved to arbitrary locations on the server using File URIs via the AlterCast web service. A malicious user can exploit this to run arbitrary commands during user logins resulting in a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-03-18 | Name : The remote web server is affected by multiple flaws. File : adobe_document_server_file_uri_access.nasl - Type : ACT_DESTRUCTIVE_ATTACK |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:20:55 |
|
2024-11-28 12:08:29 |
|
2021-05-04 12:03:47 |
|
2021-04-22 01:04:20 |
|
2020-05-23 00:17:30 |
|
2018-10-18 21:20:01 |
|
2017-07-20 09:23:25 |
|
2016-06-28 15:39:46 |
|
2016-04-26 14:23:44 |
|
2014-02-17 10:34:59 |
|
2013-05-11 10:51:20 |
|