CVE-2014-3460

critical

Description

Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.

References

http://zerodayinitiative.com/advisories/ZDI-14-134/

http://www.securitytracker.com/id/1030434

http://www.securityfocus.com/bid/67487

http://www.novell.com/support/kb/doc.php?id=7015183

http://secunia.com/advisories/58635

Details

Source: Mitre, NVD

Published: 2014-05-20

Updated: 2021-04-13

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical