7.5
CVSSv2

CVE-2007-1588

Published: 21/03/2007 Updated: 15/11/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote malicious users to execute CGI programs with unintended privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

myserver myserver 0.8.5