Vulnerabilities > CVE-2003-1122 - Unspecified vulnerability in Scriptlogic 4.01
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN scriptlogic
nessus
Summary
ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | SCRIPTLOGIC_HIDDEN_SHARE.NASL |
description | The remote host has an accessible LOGS$ share. ScriptLogic creates this share to store the logs, but does not properly set the permissions on it. As a result, anyone can use it to read or modify, or possibly execute code. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11561 |
published | 2003-05-04 |
reporter | This script is Copyright (C) 2003-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11561 |
title | ScriptLogic $LOGS Share Remote Information Disclosure |
code |
|
References
- http://www.kb.cert.org/vuls/id/813737
- http://www.kb.cert.org/vuls/id/813737
- http://www.kb.cert.org/vuls/id/CRDY-5EXQT9
- http://www.kb.cert.org/vuls/id/CRDY-5EXQT9
- http://www.securityfocus.com/bid/7476
- http://www.securityfocus.com/bid/7476
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11922
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11922