Vulnerabilities > CVE-2001-1487 - Local Security vulnerability in qpopper

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
qualcomm
exploit available

Summary

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

Vulnerable Configurations

Part Description Count
Application
Qualcomm
1

Exploit-Db

descriptionQPopper 4.0.x PopAuth Trace File Shell Command Execution Vulnerability. CVE-2001-1487. Remote exploit for unix platform
idEDB-ID:21185
last seen2016-02-02
modified2001-12-18
published2001-12-18
reporterIhaQueR
sourcehttps://www.exploit-db.com/download/21185/
titleQPopper 4.0.x PopAuth Trace File Shell Command Execution Vulnerability