Exploit QNX RTOS 4.25 - 'CRTTrap' File Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21499
Проверка EDB
  1. Пройдено
Автор
SIMON OUELLETTE
Тип уязвимости
LOCAL
Платформа
LINUX
CVE
cve-2002-0793
Дата публикации
2002-05-31
Код:
source: https://www.securityfocus.com/bid/4901/info

The QNX RTOS crttrap binary includes a command-line option for specifying a configuration file. crttrap is installed setuid by default. crttrap Local attackers may specify an arbitrary system file in place of the configuration file and crttrap will disclose the contents of the arbitrary file. 

crttrap -c /etc/shadow
 
Источник
www.exploit-db.com

Похожие темы