CVE-2013-3626
Published Nov 6, 2013
Last updated 11 years ago
Overview
- Description
- Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B731D1E-3FF0-4F54-9EE9-F5C7B3478B09" }, { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01AFC3F5-6D91-44EE-AC01-846CEED7F5F2" }, { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BF7B73D-1979-4DCC-B8C4-4615DE56B685" }, { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A0E87D5-5080-4C15-A68E-CC86F10B301F" }, { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6F6CDE49-7CC9-4A35-89F7-650A43B17EDE" }, { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC00941D-DD5C-4B2D-AF1A-47ED42257A51" }, { "criteria": "cpe:2.3:a:attachmate:verastream_host_integrator:7.5:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3193DFF-6312-4BF4-9E0C-8C3423EEDBD2" } ], "operator": "OR" } ] } ]