PT-2007-2292 · Syscp · Syscp

Publicado

2007-02-08

·

Atualizado

2018-10-16

·

CVE-2007-0849

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SysCP versions 1.2.15 and earlier
Description: The issue arises from improper quoting of pathnames in user home directories by the cronscript.php script. This allows local users to elevate privileges by inserting shell metacharacters into a directory name and then using the control panel to protect that directory.
Recommendations: For SysCP versions 1.2.15 and earlier, consider restricting access to the cronscript.php script until a proper fix is applied, and avoid using the control panel to protect directories with potentially malicious names.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0849

Produtos afetados

Syscp