ID

VAR-200204-0025


CVE

CVE-2002-0160


TITLE

Cisco Secure Access Control Server (ACS) Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200204-033

DESCRIPTION

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002

Trust: 0.99

sources: NVD: CVE-2002-0160 // VULHUB: VHN-4554

AFFECTED PRODUCTS

vendor:ciscomodel:secure access control serverscope:eqversion:2.6.4

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:3.0.1

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:2.6.3

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:3.0

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:2.6

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:2.6.2

Trust: 1.6

sources: CNNVD: CNNVD-200204-033 // NVD: CVE-2002-0160

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0160
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200204-033
value: MEDIUM

Trust: 0.6

VULHUB: VHN-4554
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-0160
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-4554
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-4554 // CNNVD: CNNVD-200204-033 // NVD: CVE-2002-0160

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-0160

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200204-033

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200204-033

EXTERNAL IDS

db:OSVDBid:5352

Trust: 1.7

db:NVDid:CVE-2002-0160

Trust: 1.7

db:CNNVDid:CNNVD-200204-033

Trust: 0.7

db:BUGTRAQid:20020403 IXSECURITY.20020316.CSADMIN_DIR.A

Trust: 0.6

db:CISCOid:20020403 WEB INTERFACE VULNERABILITIES IN CISCO SECURE ACS FOR WINDOWS

Trust: 0.6

db:VULHUBid:VHN-4554

Trust: 0.1

sources: VULHUB: VHN-4554 // CNNVD: CNNVD-200204-033 // NVD: CVE-2002-0160

REFERENCES

url:http://www.cisco.com/warp/public/707/acs-win-web.shtml

Trust: 2.7

url:http://www.osvdb.org/5352

Trust: 2.7

url:http://marc.info/?l=bugtraq&m=101786689128667&w=2

Trust: 2.1

url:http://marc.theaimsgroup.com/?l=bugtraq&m=101786689128667&w=2

Trust: 0.6

sources: VULHUB: VHN-4554 // CNNVD: CNNVD-200204-033 // NVD: CVE-2002-0160

SOURCES

db:VULHUBid:VHN-4554
db:CNNVDid:CNNVD-200204-033
db:NVDid:CVE-2002-0160

LAST UPDATE DATE

2024-11-22T23:03:17.249000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-4554date:2016-10-18T00:00:00
db:CNNVDid:CNNVD-200204-033date:2005-05-02T00:00:00
db:NVDid:CVE-2002-0160date:2024-11-20T23:38:27.067

SOURCES RELEASE DATE

db:VULHUBid:VHN-4554date:2002-04-22T00:00:00
db:CNNVDid:CNNVD-200204-033date:2002-04-22T00:00:00
db:NVDid:CVE-2002-0160date:2002-04-22T04:00:00