Vulnerability Name: | CVE-2008-0656 (CCN-40277) | ||||||||
Assigned: | 2008-02-05 | ||||||||
Published: | 2008-02-05 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Feb 05 2008 - 12:57:53 CST Arbitrary file overwrite in Documentum Administrator / Documentum Webtop Source: MITRE Type: CNA CVE-2008-0656 Source: CCN Type: SA28810 Documentum Administrator/Webtop "dmclTrace.jsp" Arbitrary File Overwrite Source: SECUNIA Type: Vendor Advisory 28810 Source: SREASON Type: UNKNOWN 3626 Source: CCN Type: SECTRACK ID: 1019305 EMC Documentum 'dmclTrace.jsp' Bug Lets Remote Users Upload Arbitrary Files and Execute Arbitrary Code Source: CCN Type: EMC Web site Documentum Product Family from EMC Source: MISC Type: UNKNOWN http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_Documentum_dmclTrace_Arbitrary_file_overwrite.pdf Source: CCN Type: OSVDB ID: 42869 Documentum Administrator / Webtop dmclTrace.jsp filename Variable Unrestricted Upload Arbitrary File Overwrite Source: BUGTRAQ Type: UNKNOWN 20080205 CYBSEC Security Advisory: Arbitrary file overwrite in Documentum Administrator / Documentum Webtop Source: BID Type: UNKNOWN 27632 Source: CCN Type: BID-27632 Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability Source: SECTRACK Type: UNKNOWN 1019305 Source: VUPEN Type: UNKNOWN ADV-2008-0439 Source: XF Type: UNKNOWN documentum-dmcltrace-file-overwrite(40277) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |