Secunia
|
|

CVE Reference: CVE-2011-1036 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2011-1036 |
|
|
Description: The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/65632 ST 1025120 SREASON http://securityreason.com/securityalert/8106 SAID Secunia Advisory: SA43377 Secunia Advisory: SA43490 MISC http://www.zerodayinitiative.com/advisories/ZDI-11-093 CONFIRM BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/516687/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/516649/100/0/threaded BID 46539 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |