>> CiscoWorks Common Services Remote Code Execution Vulnerability
Title : CiscoWorks Common Services Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-1687 CVE ID : CVE-2008-2054
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-28
Technical Description
A vulnerability has been identified in CiscoWorks Common Services, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing user-supplied data, which could allow a remote attacker to execute arbitrary code on the user client machine. No further details have been disclosed.
Upgrade to CiscoWorks Common Services version 3.2 or apply patches (cwcs3.x-sol-CSCsm77245-0.tar.gz for Solaris versions, and cwcs3.x-win-CSCsm77245-0.zip for Windows versions) : http://www.cisco.com/pcgi-bin/tablebuild.pl/cw2000-cd-one References