Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified parameters to the ScheduleTask method.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/70755 - | |
References | () http://secunia.com/advisories/43143 - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/516103/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/45946 - | |
References | () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110131_00 - | |
References | () http://www.vupen.com/english/advisories/2011/0259 - Vendor Advisory | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-11-037 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/65040 - |
Information
Published : 2011-02-02 01:00
Updated : 2024-11-21 01:19
NVD link : CVE-2010-3719
Mitre link : CVE-2010-3719
CVE.ORG link : CVE-2010-3719
JSON object : View
Products Affected
symantec
- im_manager
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')