Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1668

Опубликовано: 13 авг. 2008
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02593
Низкий

10 Critical

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information.

EPSS

Процентиль: 85%
0.02593
Низкий

10 Critical

CVSS2

Дефекты

CWE-264