1 results (0.046 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command. South River Technologies WebDrive v9.02 build 2232 instala el servicio de disco remoto sin un descriptor de seguridad, lo que permite a usuarios locales (1) parar el servicio a través del comando "stop", (2) ejecutar comandos arbitrarios como SYSTEM mediante el uso del comando "config" para modificar la variable "binPatch", o (3) reiniciar el servicio a través del comando "Start". • https://www.exploit-db.com/exploits/11264 http://osvdb.org/59080 http://retrogod.altervista.org/9sg_south_river_priv.html http://secunia.com/advisories/37083 http://www.securityfocus.com/archive/1/507323/100/0/threaded http://www.vupen.com/english/advisories/2009/2994 https://exchange.xforce.ibmcloud.com/vulnerabilities/53885 • CWE-264: Permissions, Privileges, and Access Controls •