Lucene search

K
cveMitreCVE-2004-1573
HistoryFeb 20, 2005 - 5:00 a.m.

CVE-2004-1573

2005-02-2005:00:00
mitre
web.nvd.nist.gov
30
aj-fork 167
php code execution
local privilege escalation
permissions vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0

Percentile

5.1%

The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.

Affected configurations

Nvd
Node
aj-forkaj-forkMatch167
OR
cutephpcutenewsMatch0.88
OR
cutephpcutenewsMatch1.3
OR
cutephpcutenewsMatch1.3.1
OR
cutephpcutenewsMatch1.3.2
OR
cutephpcutenewsMatch1.3.6
VendorProductVersionCPE
aj-forkaj-fork167cpe:2.3:a:aj-fork:aj-fork:167:*:*:*:*:*:*:*
cutephpcutenews0.88cpe:2.3:a:cutephp:cutenews:0.88:*:*:*:*:*:*:*
cutephpcutenews1.3cpe:2.3:a:cutephp:cutenews:1.3:*:*:*:*:*:*:*
cutephpcutenews1.3.1cpe:2.3:a:cutephp:cutenews:1.3.1:*:*:*:*:*:*:*
cutephpcutenews1.3.2cpe:2.3:a:cutephp:cutenews:1.3.2:*:*:*:*:*:*:*
cutephpcutenews1.3.6cpe:2.3:a:cutephp:cutenews:1.3.6:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2004-1573