Vulnerabilities > CVE-2001-0823 - Symbolic Link vulnerability in SGI Performance Co-Pilot pmpost

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
sgi
exploit available

Summary

The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).

Exploit-Db

descriptionSGI Performance Co-Pilot 2.1.x/2.2 pmpost Symbolic Link Vulnerability. CVE-2001-0823 . Local exploit for irix platform
idEDB-ID:20937
last seen2016-02-02
modified2001-06-18
published2001-06-18
reporterIhaQueR
sourcehttps://www.exploit-db.com/download/20937/
titleSGI Performance Co-Pilot 2.1.x/2.2 pmpost Symbolic Link Vulnerability