Flash Media < 3.0.4/3.5.2 Privilege Escalation

High Nessus Network Monitor Plugin ID 5011

Synopsis

The remote host is vulnerable to a remote 'privilege escalation' flaw

Description

The remote host is running Flash Media server. This version of Flash Media server is vulnerable to a flaw wherein malicious script code can be injected and executed via an RPC call. An attacker, exploiting this flaw, would need access to the application port and the ability to send malformed requests to the service port. An attacker, exploiting this flaw, would be able to escalate privileges on the remote system.

Solution

Adobe has released Flash Media Server versions 3.04 and 3.5.2 to address these flaws

See Also

http://www.adobe.com/support/security/bulletins/apsb09-05.html

Plugin Details

Severity: High

ID: 5011

Family: Web Servers

Published: 2004/08/18

Modified: 2018/09/16

Dependencies: 4378, 4379

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:flash_media_server

Reference Information

CVE: CVE-2009-1365

BID: 34790