Vulnerabilities > CVE-2006-5852 - Local Security vulnerability in Openbase

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
openbase-international-ltd
exploit available

Summary

Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.

Exploit-Db

descriptionXcode OpenBase <= 10.0.0 (unsafe system call) Local Root Exploit (OSX). CVE-2006-5852. Local exploit for osx platform
fileexploits/osx/local/2738.pl
idEDB-ID:2738
last seen2016-01-31
modified2006-11-08
platformosx
port
published2006-11-08
reporterKevin Finisterre
sourcehttps://www.exploit-db.com/download/2738/
titleXcode OpenBase <= 10.0.0 unsafe system call Local Root Exploit OSX
typelocal