CVE-2010-3719
high · 8.5Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified parameters to the ScheduleTask method.
8.5
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2011-02-02
Published
AV:N/AC:M/Au:S/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| symantec | im_manager | <= 8.4.16 |
| symantec | im_manager | 6.0 |
| symantec | im_manager | 6.5 |
| symantec | im_manager | 7.0 |
| symantec | im_manager | 7.5 |
| symantec | im_manager | 8.3 |
| symantec | im_manager | 8.4.0 |
| symantec | im_manager | 8.4.1 |
| symantec | im_manager | 8.4.2 |
| symantec | im_manager | 8.4.5 |
| symantec | im_manager | 8.4.6 |
| symantec | im_manager | 8.4.7 |
| symantec | im_manager | 8.4.8 |
| symantec | im_manager | 8.4.9 |
| symantec | im_manager | 8.4.10 |
| symantec | im_manager | 8.4.11 |
| symantec | im_manager | 8.4.12 |
| symantec | im_manager | 8.4.13 |
| symantec | im_manager | 8.4.15 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/70755
- http://secunia.com/advisories/43143
- http://www.securityfocus.com/archive/1/516103/100/0/threaded
- http://www.securityfocus.com/bid/45946
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110131_00
- http://www.vupen.com/english/advisories/2011/0259
- http://www.zerodayinitiative.com/advisories/ZDI-11-037
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65040
- http://osvdb.org/70755
- http://secunia.com/advisories/43143
- http://www.securityfocus.com/archive/1/516103/100/0/threaded
- http://www.securityfocus.com/bid/45946
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110131_00
- http://www.vupen.com/english/advisories/2011/0259
- http://www.zerodayinitiative.com/advisories/ZDI-11-037
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65040
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-3719