Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gx3r-q563-w43q

Опубликовано: 22 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.

Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

CVSS3: 7.8
nvd
почти 6 лет назад

Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.

EPSS

Процентиль: 12%
0.0004
Низкий