Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2010-3692 | First vendor Publication | 2010-10-07 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3692 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12588 | |||
Oval ID: | oval:org.mitre.oval:def:12588 | ||
Title: | DSA-2172-1 moodle -- several | ||
Description: | Several vulnerabilties have been discovered in phpCAS, a CAS client library for PHP. The Moodle course management system includes a copy of phpCAS. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2172-1 CVE-2010-2795 CVE-2010-2796 CVE-2010-3690 CVE-2010-3691 CVE-2010-3692 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | moodle |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-03-09 | Name : Debian Security Advisory DSA 2172-1 (moodle) File : nvt/deb_2172_1.nasl |
2010-12-02 | Name : Fedora Update for php-pear-CAS FEDORA-2010-15796 File : nvt/gb_fedora_2010_15796_php-pear-CAS_fc14.nasl |
2010-11-16 | Name : Fedora Update for glpi FEDORA-2010-16905 File : nvt/gb_fedora_2010_16905_glpi_fc12.nasl |
2010-11-16 | Name : Fedora Update for glpi FEDORA-2010-16912 File : nvt/gb_fedora_2010_16912_glpi_fc13.nasl |
2010-10-22 | Name : Fedora Update for php-pear-CAS FEDORA-2010-15943 File : nvt/gb_fedora_2010_15943_php-pear-CAS_fc13.nasl |
2010-10-22 | Name : Fedora Update for php-pear-CAS FEDORA-2010-15970 File : nvt/gb_fedora_2010_15970_php-pear-CAS_fc12.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
68519 | phpCAS client.php Callback Function PGTiou Parameter Traversal Arbitrary File... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-02-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2172.nasl - Type : ACT_GATHER_INFO |
2010-11-07 | Name : The remote Fedora host is missing a security update. File : fedora_2010-16905.nasl - Type : ACT_GATHER_INFO |
2010-11-07 | Name : The remote Fedora host is missing a security update. File : fedora_2010-16912.nasl - Type : ACT_GATHER_INFO |
2010-10-20 | Name : The remote Fedora host is missing a security update. File : fedora_2010-15943.nasl - Type : ACT_GATHER_INFO |
2010-10-20 | Name : The remote Fedora host is missing a security update. File : fedora_2010-15970.nasl - Type : ACT_GATHER_INFO |
2010-10-15 | Name : The remote Fedora host is missing a security update. File : fedora_2010-15796.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:26 |
|
2024-11-28 12:23:07 |
|
2021-05-05 01:07:33 |
|
2021-05-04 12:12:40 |
|
2021-04-22 01:13:15 |
|
2020-05-23 01:42:47 |
|
2020-05-23 00:26:37 |
|
2016-04-26 20:08:44 |
|
2014-02-17 10:57:47 |
|
2013-05-10 23:34:06 |
|