Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2wv-vpg7-fc49

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.

scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.

EPSS

Процентиль: 31%
0.00117
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.

EPSS

Процентиль: 31%
0.00117
Низкий