Vulnerabilities > CVE-2003-1121
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
Summary
Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | SMB_SVC_SCRIPTLOGIC.NASL |
description | The ScriptLogic service is running on this port. There is a flaw in versions up to 4.05 of this service which may allow an attacker to write arbitrary values in the remote registry with administrator privileges, which can be used to gain a shell on this host. *** Since Nessus was unable to determine the version of ScriptLogic *** running on this host, this might be a false positive. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11562 |
published | 2003-05-04 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11562 |
title | ScriptLogic Multiple Service Remote Privilege Escalation |
code |
|
References
- http://www.kb.cert.org/vuls/id/231705
- http://www.kb.cert.org/vuls/id/231705
- http://www.kb.cert.org/vuls/id/609137
- http://www.kb.cert.org/vuls/id/609137
- http://www.kb.cert.org/vuls/id/CRDY-5EXQRP
- http://www.kb.cert.org/vuls/id/CRDY-5EXQRP
- http://www.kb.cert.org/vuls/id/CRDY-5EXQSV
- http://www.kb.cert.org/vuls/id/CRDY-5EXQSV
- http://www.securityfocus.com/bid/7475
- http://www.securityfocus.com/bid/7475
- http://www.securityfocus.com/bid/7477
- http://www.securityfocus.com/bid/7477
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11921
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11921