7.2
CVSSv2

CVE-2000-0680

Published: 20/10/2000 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.

Vulnerable Product Search on Vulmon Subscribe to Product

cvs cvs 1.10.8

Exploits

source: wwwsecurityfocuscom/bid/1524/info A CVS committer can execute arbitrary binaries by using Checkinprog Usually CVS/Checkinprog in a working directory is copied from CVSROOT/modules when the directory is "checkout"ed and it is sent back to the server and executed with committing Note that when it is executed, committed files exi ...