Vulnerabilities > CVE-2014-2387 - Exposure of Resource to Wrong Sphere vulnerability in multiple products

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities

Common Weakness Enumeration (CWE)

Seebug

bulletinFamilyexploit
descriptionBugtraq ID:66214 CVE ID:CVE-2014-2387 Pen是一个简单的负载平衡器,支持基础协议的TCP如HTTP或SMTP 。 Pen "/tmp/webfile.html"和"/tmp/penctl.cgi"脚本不安全创建临时文件,允许本地攻击者利用漏洞进行符号链接攻击,可破坏系统文件等。 0 Pen 目前没有详细解决方案提供: http://siag.nu/pen/
idSSV:61814
last seen2017-11-19
modified2014-03-17
published2014-03-17
reporterRoot
titlePen 'penctl.cgi'多个不安全临时文件创建漏洞