| |
| |
SecuriTeam - CiscoWorks 2000 Privilege Escalation Vulnerabilities (CiscoWorks Application Vulnerabilities) |
 | | CiscoWorks Common Management Foundation (CMF), also packaged as part of CiscoWorks CD One, provides an application infrastructure foundation, allowing all CiscoWorks applications to share a common model for data storage, login, user role definitions, access privileges, and security protocols, as well as for navigation and launch management. |
 | | CiscoWorks CD One is included as the base for all CiscoWorks management solutions, such as the LAN Management Solution, Routed WAN Management Solution, Small Network Management Solution, and VPN/Security Management Solution. |
 | | The second vulnerability permits an authenticated user of the CiscoWorks application to run arbitrary commands on the CiscoWorks server as "casuser", the username under which the application runs. |
| www.securiteam.com /securitynews/5FP0B15AUS.html (954 words) |
|