Vulnerabilities > CVE-2007-0849 - Unspecified vulnerability in Syscp Team Syscp

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
syscp-team
exploit available

Summary

scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.

Vulnerable Configurations

Part Description Count
Application
Syscp_Team
1

Exploit-Db

descriptionSYSCP 1.2.15 System Control Panel CronJob Arbitrary Code Execution Vulnerability. CVE-2007-0849. Webapps exploit for php platform
idEDB-ID:29571
last seen2016-02-03
modified2007-02-07
published2007-02-07
reporterDaniel Schulte
sourcehttps://www.exploit-db.com/download/29571/
titleSYSCP 1.2.15 System Control Panel CronJob Arbitrary Code Execution Vulnerability