CVE-2007-1370
 
Severity Score
6.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.
Zend Platform 2.2.3 y anteriores tiene una propiedad incorrecta para scd.sh y otros ciertos archivos, lo caul permite a usuarios locales ganar privilegios de root a través de la modificación de archivos. NOTA: esto solamente ocurre cuando safe_mode y open_basedir están desactivados; otras configuraciones requieren el apalancamiento para otras vulnerabilidades.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-03-09 CVE Reserved
- 2007-03-09 CVE Published
- 2024-08-01 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/24501 | Third Party Advisory | |
http://www.osvdb.org/32772 | Vdb Entry | |
http://www.securityfocus.com/bid/22801 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/0829 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32825 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.php-security.org/MOPB/BONUS-06-2007.html | 2017-07-29 |
URL | Date | SRC |
---|---|---|
http://www.zend.com/products/zend_platform/security_vulnerabilities | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zend Search vendor "Zend" | Zend Platform Search vendor "Zend" for product "Zend Platform" | 2.2.1a Search vendor "Zend" for product "Zend Platform" and version "2.2.1a" | - |
Affected
| ||||||
Zend Search vendor "Zend" | Zend Platform Search vendor "Zend" for product "Zend Platform" | 2.2.1a Search vendor "Zend" for product "Zend Platform" and version "2.2.1a" | a |
Affected
|