4.6
CVSSv2

CVE-2000-0015

Published: 31/12/1999 Updated: 10/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CascadeView TFTP server allows local users to gain privileges via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

ascend cascadeview ux 1.0

Exploits

source: wwwsecurityfocuscom/bid/910/info The tftpd bundled with CascadeView for Ascend's B-STDX 8000/9000 network devices creates a log in /tmp called tftpd_xfer_statuslog If /tmp/tftpd_xfer_statuslog already exists as a symbolic link, tftpd will follow it and overwrite any data it points to (it runs as root) It is possible for an att ...