Lucene search

K
cve[email protected]CVE-2004-0160
HistorySep 01, 2004 - 4:00 a.m.

CVE-2004-0160

2004-09-0104:00:00
web.nvd.nist.gov
23
synaesthesia
cve-2004-0160
arbitrary code execution
symlink attack
information security

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0

Percentile

5.1%

Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

Affected configurations

NVD
Node
synaesthesiasynaesthesiaMatch2.1.0
OR
synaesthesiasynaesthesiaMatch2.1.1
OR
synaesthesiasynaesthesiaMatch2.1.2
OR
synaesthesiasynaesthesiaMatch2.2
VendorProductVersionCPE
synaesthesiasynaesthesia2.1.2cpe:/a:synaesthesia:synaesthesia:2.1.2:::
synaesthesiasynaesthesia2.2cpe:/a:synaesthesia:synaesthesia:2.2:::
synaesthesiasynaesthesia2.1.0cpe:/a:synaesthesia:synaesthesia:2.1.0:::
synaesthesiasynaesthesia2.1.1cpe:/a:synaesthesia:synaesthesia:2.1.1:::

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0

Percentile

5.1%