Описание
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
Ссылки
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:adobe:version_cue:gold:*:mac_os_x:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00669
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
EPSS
Процентиль: 71%
0.00669
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other