VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-1907
consona_dynamic_agent, consona_live_assistance, consona_subscriber_assistance: The SdcUser.TgConCtl ActiveX control in tgctlcm.dll...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1907

Original

The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-12
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-12




Affected Product Tags
cpe:/a:consona:consona_dynamic_agent:-:-:enterprise
cpe:/a:consona:consona_dynamic_agent:-:-:marketing
cpe:/a:consona:consona_dynamic_agent:-:-:support
cpe:/a:consona:consona_live_assistance
cpe:/a:consona:consona_subscriber_assistance
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
VU#602801




BUGTRAQ 20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities




MISC http://www.wintercore.com/downloads/rootedcon_0day.pdf




MISC http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html




Vulnerability Type Information Leak / Disclosure (CWE-200)





Copyright © 2010 JPCERT/CC All Rights Reserved.