4.6
CVSSv2

CVE-2006-5852

Published: 10/11/2006 Updated: 19/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Untrusted search path vulnerability in openexec in OpenBase SQL prior to 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbase international ltd openbase 10.0

openbase international ltd openbase 7.0.15

openbase international ltd openbase 8.0.4

openbase international ltd openbase 9.1.5

Exploits

#!/usr/bin/perl # # wwwdigitalmunitioncom # written by kf (kf_lists[at]digitalmunition[dot]com) # # <= ftp://wwwopenbasecom/pub/OpenBase_100 (vulnerable) ? # # This is some fairly blatant and retarded use of system() # # cd cp chmod chown rm mkdir and killall appear as strings in the binary hrmm can you cay system() ! # -restart -Mac ...