Overview
There is a vulnerability in the ServletExec subcomponent of the Cisco Collaboration Server (CCS) that could allow an attacker to upload arbitrary files to the server.
Description
The Cisco Collaboration Server (CCS) is designed to provide interactive customer support (web page sharing, application sharing, text chat, etc.) through a web browser. There is a vulnerability in the UploadServlet of the ServletExec subcomponent of CCS. This vulnerability could allow a remote attacker to upload arbitrary files to the server and subsequently execute those files. As noted in the Cisco Advisory, you can test your CCS to determine if it is vulnerable by attempting to load the following URL: |
Impact
A remote attacker could upload arbitrary files to the CCS and potentially gain administrative privileges. |
Solution
Apply patch |
Manual Instructions to Patch CCS 4.x
CCS 5.x is not vulnerable and these manual instructions do not apply. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cisco.com/warp/public/707/cisco-sa-20040630-CCS.shtml
- http://www.cisco.com/warp/public/180/prod_plat/cust_cont/cis/web_collaboration.html
- http://secunia.com/advisories/11979/
- http://www.newatlanta.com/biz/c/products/servletexec/self_help/faq/detail?faqId=195
- http://www.cisco.com/application/pdf/en/us/guest/products/ps1001/c1067/ccmigration_09186a008020f9b4.pdf
Acknowledgements
This vulnerability was reported by the Cisco Systems Product Security Incident Response Team (PSIRT).
This document was written by Damon Morda.
Other Information
CVE IDs: | None |
Severity Metric: | 8.93 |
Date Public: | 2004-06-30 |
Date First Published: | 2004-07-09 |
Date Last Updated: | 2004-07-09 14:42 UTC |
Document Revision: | 12 |