Vulnerabilities > CVE-2007-0849 - Unspecified vulnerability in Syscp Team Syscp
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN syscp-team
exploit available
Summary
scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | SYSCP 1.2.15 System Control Panel CronJob Arbitrary Code Execution Vulnerability. CVE-2007-0849. Webapps exploit for php platform |
id | EDB-ID:29571 |
last seen | 2016-02-03 |
modified | 2007-02-07 |
published | 2007-02-07 |
reporter | Daniel Schulte |
source | https://www.exploit-db.com/download/29571/ |
title | SYSCP 1.2.15 System Control Panel CronJob Arbitrary Code Execution Vulnerability |
References
- http://osvdb.org/33128
- http://osvdb.org/33128
- http://secunia.com/advisories/24102
- http://secunia.com/advisories/24102
- http://www.securityfocus.com/archive/1/459397/100/0/threaded
- http://www.securityfocus.com/archive/1/459397/100/0/threaded
- http://www.securityfocus.com/bid/22453
- http://www.securityfocus.com/bid/22453
- http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP
- http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP