0x01 : Vendor description of software
-------------------------------------
From the vendor website:
"evalSMSI is a web application, developed in PHP / MySQL, to evaluate the
Information Security Management System for some entities."
0x02 : Vulnerability details
----------------------------
evalsmsi 2.1.03 contains multiple vulnerabilities.
CA Gateway Security 9.0
How to determine if the installation is affected
- From the CA Gateway Security Management Console, select About to view
version information. If the version displayed is less than 8.1.0.69,
the installation is vulnerable.
Solution
update that shipped with AVPack 8.1.3.5 on the 09/01/2009
14/01/2009 : Avira states that all products have been affected
except "Securityy Management Center" and the "Internet Update
Manager". "Das bedeutet im Prinzip wirklich alle Produkte, ausser
Produkte wie eben das Security Management Center oder der Internet
Update Manager"
14/01/2009 : Release of this advisory