CVE-2011-0966: Path Traversal
Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0966?
CVE-2011-0966 is classified as a high severity vulnerability due to its directory traversal exploitation potential.
How do I fix CVE-2011-0966?
To fix CVE-2011-0966, upgrade CiscoWorks Common Services to version 3.4 or later.
What systems are affected by CVE-2011-0966?
CVE-2011-0966 affects CiscoWorks Common Services 3.3 and earlier versions including 1.0, 2.2, 3.0, and their variants.
What type of attack can exploit CVE-2011-0966?
CVE-2011-0966 can be exploited by remote attackers to read arbitrary files through directory traversal techniques.
Is there a workaround for CVE-2011-0966?
Implementing strict input validation and disabling unnecessary services can mitigate some risks associated with CVE-2011-0966.