Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CA eTrust Security Command Center和eTrust Audit多个安全漏洞
Vulnerability Description
CA eTrust Security Command Center用于实时监控和管理企业安全的各个方面,eTrust Audit能收集有关企业级安全和系统的审计信息。 上述两个安全产品中存在多个安全漏洞,具体如下: 如果向ePPIServlet脚本发送了引号字符的话,eTrust Security Command Center就不会正确地处理PIProfile函数,导致泄漏Web主目录路径。 eTrust Security Command Center没有正确地验证getadhochtml函数所生成临时文
CVSS Information
N/A
Vulnerability Type
N/A