Lucene search

K
cveRedhatCVE-2010-2945
HistoryAug 30, 2010 - 8:00 p.m.

CVE-2010-2945

2010-08-3020:00:02
CWE-16
redhat
web.nvd.nist.gov
36
slim
configuration
default_path
local users
privileges
trojan horse
slim.conf
cfg.cpp
cve-2010-2945
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.8

Confidence

High

EPSS

0

Percentile

5.1%

The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.

Affected configurations

Nvd
Node
simone_rotaslim_simple_login_managerRange1.3.1
OR
simone_rotaslim_simple_login_managerMatch1.0.0
OR
simone_rotaslim_simple_login_managerMatch1.1.0
OR
simone_rotaslim_simple_login_managerMatch1.2.0
OR
simone_rotaslim_simple_login_managerMatch1.2.1
OR
simone_rotaslim_simple_login_managerMatch1.2.2
OR
simone_rotaslim_simple_login_managerMatch1.2.3
OR
simone_rotaslim_simple_login_managerMatch1.2.4
OR
simone_rotaslim_simple_login_managerMatch1.2.5
OR
simone_rotaslim_simple_login_managerMatch1.2.6
OR
simone_rotaslim_simple_login_managerMatch1.3.0
VendorProductVersionCPE
simone_rotaslim_simple_login_manager*cpe:2.3:a:simone_rota:slim_simple_login_manager:*:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.0.0cpe:2.3:a:simone_rota:slim_simple_login_manager:1.0.0:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.1.0cpe:2.3:a:simone_rota:slim_simple_login_manager:1.1.0:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.0cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.0:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.1cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.1:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.2cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.2:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.3cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.3:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.4cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.4:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.5cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.5:*:*:*:*:*:*:*
simone_rotaslim_simple_login_manager1.2.6cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.8

Confidence

High

EPSS

0

Percentile

5.1%