Vulnerabilities > CVE-2005-1307 - Local Privilege Escalation vulnerability in Adobe Version Cue

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
adobe
apple
exploit available

Summary

The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.

Vulnerable Configurations

Part Description Count
Application
Adobe
1
OS
Apple
1

Exploit-Db

descriptionMac OS X Adobe Version Cue Local Root Exploit. CVE-2005-1307. Local exploit for osx platform
idEDB-ID:680
last seen2016-01-31
modified2004-12-08
published2004-12-08
reporterJonathan Bringhurst
sourcehttps://www.exploit-db.com/download/680/
titleMac OS X Adobe Version Cue - Local Root Exploit