E09-43p01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2009
Description
Symantec System Center Alert Management System is prone to a remote
command-injection vulnerability because the application fails to
properly sanitize user-supplied input, specifically with regards to the
CreateProcessA function. This strike delivers an attack
which is consistent with exploiting this vulnerability and achieves
arbitrary command execution.
CVE
References
http://www.metasploit.com/modules/auxiliary/admin/symantec/ams_xfr