Vulnerabilities > CVE-2000-1127 - Local Arbitrary File Read vulnerability in HP Hp-Ux 10.20

047910
CVSS 3.6 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
hp
exploit available

Summary

registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.

Vulnerable Configurations

Part Description Count
OS
Hp
1

Exploit-Db

descriptionHP-UX 10.20 registrar Local Arbitrary File Read Vulnerability. CVE-2000-1127. Local exploit for hp-ux platform
idEDB-ID:20386
last seen2016-02-02
modified2000-11-08
published2000-11-08
reporterJ.A. Gutierrez
sourcehttps://www.exploit-db.com/download/20386/
titleHP-UX 10.20 registrar Local Arbitrary File Read Vulnerability