Vulnerabilities > CVE-2000-1072 - Unspecified vulnerability in Netscape Iplanet Ical 2.1

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
netscape
exploit available

Summary

iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.

Vulnerable Configurations

Part Description Count
Application
Netscape
1

Exploit-Db

descriptionNetscape iCal 2.1 Patch2 iPlanet iCal 'iplncal.sh' Permissions Vulnerability. CVE-2000-1072. Local exploit for solaris platform
idEDB-ID:20275
last seen2016-02-02
modified2000-10-10
published2000-10-10
reporter@stake
sourcehttps://www.exploit-db.com/download/20275/
titleNetscape iCal 2.1 Patch2 iPlanet iCal 'iplncal.sh' Permissions Vulnerability