PT-2012-4727 · None · Extplorer
Andreas Beckmann
+1
·
Published
2012-08-07
·
Updated
2012-08-08
·
CVE-2012-3454
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eXtplorer version 2.1.0b6
Description
The issue concerns the use of world-writable permissions for the /var/lib/extplorer/ftp tmp directory. This setup allows local users to delete or overwrite arbitrary files.
Recommendations
For version 2.1.0b6, change the permissions of the /var/lib/extplorer/ftp tmp directory to prevent world-writable access, restricting write permissions to only the necessary users or groups.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Extplorer