Exploit Sun Solaris 2.5/2.6/7.0/8/9 AT Command - Arbitrary File Deletion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22203
Проверка EDB
  1. Пройдено
Автор
WOJCIECH PURCZYNSKI
Тип уязвимости
LOCAL
Платформа
SOLARIS
CVE
cve-2003-1073
Дата публикации
2003-01-27
Код:
source: https://www.securityfocus.com/bid/6692//info

The at utility shipped with Sun Solaris may be prone to an issue which may allow attackers to delete arbitrary files on the system.

The vulnerability occurs when using at with the '-r' option. This option is used to remove previously scheduled at jobs. The vulnerability exists because at does not properly sanitize parameters submitted as part of the -r commandline option.

A local attacker can cause at to delete arbitrary files on the system.

/usr/bin/at -r ../../../../tmp/foo
 
Источник
www.exploit-db.com

Похожие темы