CVE-2011-4532 Information
Feb 14, 2021
cve
Description
Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method.
Reference
http://aluigi.altervista.org/adv/almsrvx_1-adv.txt http://support.automation.siemens.com/WW/llisapi.dll/57252401?func=ll&objId=57252401&objAction=csView&nodeid0=17323948&lang=en&siteid=cseus&aktprim=0&extranet=standard&viewreg=WW&load=content http://support.automation.siemens.com/WW/view/en/114358 http://www.us-cert.gov/control_systems/pdf/ICSA-11-361-01.pdf
Share on: