Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-0449

Опубликовано: 07 авг. 2003
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:progress:database:9.1:*:*:*:*:*:*:*

EPSS

Процентиль: 8%
0.00035
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.

EPSS

Процентиль: 8%
0.00035
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other