ID

VAR-200408-0057


CVE

CVE-2004-0650


TITLE

New Atlanta ServletExec Unauthorized Access Vulnerability

Trust: 0.9

sources: BID: 10639 // CNNVD: CNNVD-200408-058

DESCRIPTION

UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL. It has been reported that New Atlanta ServletExec is affected by an unauthorized access vulnerability; fixes are available. This issue is due to an access validation error. This issue would allow an attacker to upload and execute files on the affected computer, facilitating unauthorized interactive access as well as other attacks. This issue might also be leveraged to cause a denial of service condition in the affected server

Trust: 1.89

sources: NVD: CVE-2004-0650 // CERT/CC: VU#718896 // BID: 10639

AFFECTED PRODUCTS

vendor:newatlantamodel:servletexecscope:eqversion:2.2

Trust: 1.6

vendor:newatlantamodel:servletexecscope:eqversion:3.0

Trust: 1.6

vendor:ciscomodel: - scope: - version: -

Trust: 0.8

vendor:ciscomodel:collaboration serverscope:eqversion:4.0

Trust: 0.3

vendor:ciscomodel:collaboration serverscope:eqversion:3.02

Trust: 0.3

vendor:ciscomodel:collaboration serverscope:eqversion:3.01

Trust: 0.3

vendor:ciscomodel:collaboration serverscope:eqversion:3.0

Trust: 0.3

vendor:ciscomodel:collaboration serverscope:neversion:5.0

Trust: 0.3

sources: CERT/CC: VU#718896 // BID: 10639 // CNNVD: CNNVD-200408-058 // NVD: CVE-2004-0650

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2004-0650
value: HIGH

Trust: 1.0

CARNEGIE MELLON: VU#718896
value: 8.93

Trust: 0.8

CNNVD: CNNVD-200408-058
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2004-0650
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CERT/CC: VU#718896 // CNNVD: CNNVD-200408-058 // NVD: CVE-2004-0650

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2004-0650

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200408-058

TYPE

access verification error

Trust: 0.6

sources: CNNVD: CNNVD-200408-058

EXTERNAL IDS

db:SECUNIAid:11979

Trust: 2.4

db:CERT/CCid:VU#718896

Trust: 2.4

db:NVDid:CVE-2004-0650

Trust: 1.9

db:BIDid:10639

Trust: 1.9

db:CISCOid:20040630 CISCO COLLABORATION SERVER VULNERABILITY

Trust: 0.6

db:XFid:16553

Trust: 0.6

db:CNNVDid:CNNVD-200408-058

Trust: 0.6

sources: CERT/CC: VU#718896 // BID: 10639 // CNNVD: CNNVD-200408-058 // NVD: CVE-2004-0650

REFERENCES

url:http://www.cisco.com/warp/public/707/cisco-sa-20040630-ccs.shtml

Trust: 2.7

url:http://secunia.com/advisories/11979/

Trust: 2.4

url:http://www.kb.cert.org/vuls/id/718896

Trust: 1.6

url:http://www.securityfocus.com/bid/10639

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/16553

Trust: 1.0

url:http://www.cisco.com/warp/public/180/prod_plat/cust_cont/cis/web_collaboration.html

Trust: 0.8

url:http://www.newatlanta.com/biz/c/products/servletexec/self_help/faq/detail?faqid=195

Trust: 0.8

url:http://www.cisco.com/application/pdf/en/us/guest/products/ps1001/c1067/ccmigration_09186a008020f9b4.pdf

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/16553

Trust: 0.6

url:http://www.newatlanta.com/

Trust: 0.3

url:http://www.newatlanta.com/products/servletexec/index.jsp

Trust: 0.3

sources: CERT/CC: VU#718896 // BID: 10639 // CNNVD: CNNVD-200408-058 // NVD: CVE-2004-0650

CREDITS

Cisco PSIRT※ psirt@cisco.com

Trust: 0.6

sources: CNNVD: CNNVD-200408-058

SOURCES

db:CERT/CCid:VU#718896
db:BIDid:10639
db:CNNVDid:CNNVD-200408-058
db:NVDid:CVE-2004-0650

LAST UPDATE DATE

2024-08-14T14:35:52.279000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#718896date:2004-07-09T00:00:00
db:BIDid:10639date:2009-07-12T05:16:00
db:CNNVDid:CNNVD-200408-058date:2005-10-20T00:00:00
db:NVDid:CVE-2004-0650date:2017-07-11T01:30:20.713

SOURCES RELEASE DATE

db:CERT/CCid:VU#718896date:2004-07-09T00:00:00
db:BIDid:10639date:2004-06-30T00:00:00
db:CNNVDid:CNNVD-200408-058date:2004-06-30T00:00:00
db:NVDid:CVE-2004-0650date:2004-08-06T04:00:00