Vulnerabilities > CVE-2001-1000 - Symbolic Link vulnerability in Merit AAA RADIUS Server rlmadmin

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
merit
exploit available

Summary

rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.

Vulnerable Configurations

Part Description Count
Application
Merit
2

Exploit-Db

descriptionMerit AAA RADIUS Server 3.8 rlmadmin Symbolic Link Vulnerability. CVE-2001-1000 . Local exploit for unix platform
idEDB-ID:21101
last seen2016-02-02
modified2001-09-07
published2001-09-07
reporterDigital Shadow
sourcehttps://www.exploit-db.com/download/21101/
titleMerit AAA RADIUS Server 3.8 rlmadmin Symbolic Link Vulnerability