CVE-2013-5486
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOTE: this can be leveraged to execute arbitrary commands by using the JBoss autodeploy functionality.
- Affected products
- Cisco Prime Data Center Network Manager, Jboss
- Cisco Prime Data Center Network Manager
- = 4.1\(2\), 4.1\(3\), 4.1\(4\), 4.1\(5\), 4.2\(1\), 4.2\(3\), 5.0\(2\), 5.0\(3\), 5.1\(1\), 5.1\(2\), 5.1\(3u\), 5.2\(2\), 5.2\(2a\), 5.2\(2b\), 5.2\(2c\), 5.2\(2e\), 6.1\(1a\), 6.1\(1b\)
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 76.0% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2013-09-23
CVE-2013-5486 at NVD
5 known exploits for CVE-2013-5486
Proof-of-concept code and exploit modules indexed by Sploitus
Cisco Prime Data Center Network Manager Arbitrary File Upload Vulnerability
Cisco Prime Data Center Network Manager Arbitrary File Upload
Cisco Prime Data Center Network Manager - Arbitrary File Upload (Metasploit)
Cisco Prime Data Center Network Manager Arbitrary File Upload
Cisco Prime Data Center Network Manager Arbitrary File Upload