7.2
CVSSv2

CVE-2003-1358

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

rs.F300 for HP-UX 10.0 up to and including 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

Vulnerable Product Search on Vulmon Subscribe to Product

hp hp-ux 10.16

hp hp-ux 10.20

hp hp-ux 11.04

hp hp-ux 11.11

hp hp-ux 10.09

hp hp-ux 10.10

hp hp-ux 11.0.4

hp hp-ux 11.00

hp hp-ux 10.00

hp hp-ux 10.24

hp hp-ux 10.26

hp hp-ux 11.20

hp hp-ux 11.22

hp hp-ux 10.01

hp hp-ux 10.08

hp hp-ux 10.30

hp hp-ux 10.34

Exploits

source: wwwsecurityfocuscom/bid/6837/info The rsF3000 binary is prone to an issue that may allow attackers to obtain unauthorized access to a vulnerable system A denial of service attack is also possible This is due to multiple instances of the system() function being used in an unsafe manner #!/bin/sh ## copyright LAST STAGE OF DELI ...