imPC@ndo IT

Tracker / CVE-2003-0732

CVE-2003-0732

High 10.0

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.

Affected products and versions

cisco ciscoworks_cd1
cisco ciscoworks_common_management_foundation
cisco resource_manager
cisco resource_manager_essentials

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References