Flash Media < 3.0.4/3.5.2 Privilege Escalation

high Nessus Network Monitor Plugin ID 5011

Synopsis

The remote host is vulnerable to a remote 'privilege escalation' flaw

Description

The remote host is running Flash Media server. This version of Flash Media server is vulnerable to a flaw wherein malicious script code can be injected and executed via an RPC call. An attacker, exploiting this flaw, would need access to the application port and the ability to send malformed requests to the service port. An attacker, exploiting this flaw, would be able to escalate privileges on the remote system.

Solution

Adobe has released Flash Media Server versions 3.04 and 3.5.2 to address these flaws

See Also

http://www.adobe.com/support/security/bulletins/apsb09-05.html

Plugin Details

Severity: High

ID: 5011

Family: Web Servers

Published: 8/18/2004

Updated: 3/6/2019

Nessus ID: 38700

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:flash_media_server

Reference Information

CVE: CVE-2009-1365

BID: 34790