CVE-2003-0731 Information

Description

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet possibly involving the \cmd\ parameter with a modifyUser value and a modified \priviledges\ parameter.

Reference

http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml http://www.securityfocus.com/archive/1/333028

Share on: