Vulnerabilities > CVE-2000-0936 - Unspecified vulnerability in Samba 2.0.7

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
samba
exploit available

Summary

Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.

Vulnerable Configurations

Part Description Count
Application
Samba
1

Exploit-Db

descriptionSAMBA 2.0.7 SWAT Logfile Permissions Vulnerability. CVE-2000-0936. Local exploit for linux platform
idEDB-ID:20341
last seen2016-02-02
modified2000-11-01
published2000-11-01
reportermiah
sourcehttps://www.exploit-db.com/download/20341/
titleSAMBA 2.0.7 SWAT Logfile Permissions Vulnerability