Summary
=======
The Cisco Internet Streamer application, part of the Cisco Content
Delivery System, contains a directory traversal vulnerability on its web
server component that allows for arbitrary file access. By exploiting
this vulnerability, an attacker may be able to read arbitrary files on
the device, outside of the web server document directory, by using a
specially crafted URL.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Cisco Security Advisory: Cisco Content Delivery System Internet
Streamer: Web Server Vulnerability
Advisory ID: cisco-sa-20110525-spcdn
Revision 1.0
|----------------------------------------------------------------+---------------------------|
| Cisco CNS Network Registrar | CSCts36064 |
|----------------------------------------------------------------+---------------------------|
| Cisco Conductor for Videoscape | CSCts32986 |
|----------------------------------------------------------------+---------------------------|
| Cisco Content Delivery Engine | CSCts36206 |
|----------------------------------------------------------------+---------------------------|
| Cisco Content Delivery System Internet Streamer | CSCts35643 |
|----------------------------------------------------------------+---------------------------|
| Cisco Detector XT DDoS Mitigation Appliance | CSCts33211 |
|----------------------------------------------------------------+---------------------------|
From [1]:
"The Cisco CSS 11500 Series Content Services Switch is a high-performance,
high-availability modular architecture for Web infrastructures. As the
premiere switch for the Cisco Web Network Services Software, the Cisco
CSS 11500 Series helps businesses to build global Web networks
optimized for content delivery and e-commerce. By activating HTTP
headers, the CSS 11500 Series helps to ensure availability, optimize
utilization, reduce latency, increase scalability, and enhance security
for Websites, server farms, cache clusters, and firewall systems."
From [2]:
===============
1) Introduction
===============
NowSMS is a commercial SMS and MMS Content Delivery Solution.
#######################################################################
=======
* CVSS Base Score: 5.53
* Product Description:
The Akamai Client Software is a software layer that securely stores and
transfers files to enhance content delivery.
* Vulnerability Description:
Akamai has become aware of a security vulnerability within the Akamai