3.6
CVSSv2

CVE-2003-1452

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 365
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Untrusted search path vulnerability in Qualcomm qpopper 4.0 up to and including 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm qpopper 4.0

qualcomm qpopper 4.0_b14

qualcomm qpopper 4.0.5

qualcomm qpopper 4.0.5_fc2

qualcomm qpopper 4.0.1

qualcomm qpopper 4.0.2

qualcomm qpopper 4.0.3

qualcomm qpopper 4.0.4

Exploits

/* ** ** Title: Qpopper v40x poppassd local root exploit ** Exploit code: 0x82-LocalQp0ppa55dc ** ** -- ** /0x82-LocalQp0ppa55d -u x82 -p mypasswd ** ** Qpopper v40x poppassd local root exploit ** by Xpl017Elz ** */ #include <stdioh> #include <stdlibh> #include <unistdh> #include <sys/ ...