CVE-2011-3310 (CNNVD-201110-516)
中文标题:
CiscoWorks Common Services 代码注入漏洞
英文标题:
The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoW...
漏洞描述
中文描述:
CiscoWorks Common Services是CiscoWorks应用所共享的通用管理服务集。 CiscoWorks Common Services在实现上存在代码注入漏洞。远程攻击者可利用此漏洞在下层操作系统上以系统级别的权限执行任意命令。 此漏洞源于CiscoWorks Home Page组件中的错误输入验证。 受到影响的应用包括: CiscoWorks LAN Management Solution Security Manager Unified Operations Manager Unified Service Monitor CiscoWorks QoS Policy Manager CiscoWorks Voice Manager
英文描述:
The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and CiscoWorks Voice Manager, allows remote authenticated users to execute arbitrary commands via a crafted URL, aka Bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | ciscoworks_common_services | * | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:*:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 2.2 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:2.2:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 3.0.5 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:3.0.5:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 3.0.6 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:3.0.6:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 3.1 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:3.1:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 3.1.1 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:3.1.1:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 3.2 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:3.2:*:*:*:*:*:*:*
|
| cisco | ciscoworks_common_services | 3.3 | - | - |
cpe:2.3:a:cisco:ciscoworks_common_services:3.3:*:*:*:*:*:*:*
|
| microsoft | windows | * | - | - |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:L/Au:S/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2011-3310 |
2025-11-11 15:18:23 | 2025-11-11 07:33:17 |
| NVD | nvd_CVE-2011-3310 |
2025-11-11 14:53:44 | 2025-11-11 07:42:06 |
| CNNVD | cnnvd_CNNVD-201110-516 |
2025-11-11 15:09:13 | 2025-11-11 07:49:56 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码注入
- cnnvd_id: 未提取 -> CNNVD-201110-516
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:S/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 9
- data_sources: ['cve'] -> ['cve', 'nvd']