Lucene search

K
nvd[email protected]NVD:CVE-2004-1162
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1162

2005-01-1005:00:00
web.nvd.nist.gov
5

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.006

Percentile

77.7%

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

Affected configurations

Nvd
Node
scponlyscponlyMatch2.0
OR
scponlyscponlyMatch2.1
OR
scponlyscponlyMatch2.3
OR
scponlyscponlyMatch2.4
OR
scponlyscponlyMatch3.0
OR
scponlyscponlyMatch3.5
OR
scponlyscponlyMatch3.8
OR
scponlyscponlyMatch3.9
OR
scponlyscponlyMatch3.11
Node
gentoolinux
VendorProductVersionCPE
scponlyscponly2.0cpe:2.3:a:scponly:scponly:2.0:*:*:*:*:*:*:*
scponlyscponly2.1cpe:2.3:a:scponly:scponly:2.1:*:*:*:*:*:*:*
scponlyscponly2.3cpe:2.3:a:scponly:scponly:2.3:*:*:*:*:*:*:*
scponlyscponly2.4cpe:2.3:a:scponly:scponly:2.4:*:*:*:*:*:*:*
scponlyscponly3.0cpe:2.3:a:scponly:scponly:3.0:*:*:*:*:*:*:*
scponlyscponly3.5cpe:2.3:a:scponly:scponly:3.5:*:*:*:*:*:*:*
scponlyscponly3.8cpe:2.3:a:scponly:scponly:3.8:*:*:*:*:*:*:*
scponlyscponly3.9cpe:2.3:a:scponly:scponly:3.9:*:*:*:*:*:*:*
scponlyscponly3.11cpe:2.3:a:scponly:scponly:3.11:*:*:*:*:*:*:*
gentoolinux*cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.006

Percentile

77.7%