7.2

CVE-2009-1462

Exploit
The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RazorcmsRazorcms Version <= 0.3
RazorcmsRazorcms Version0.2
RazorcmsRazorcms Version0.3 Updaterc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.319
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=full-disclosure&m=123990481506680&w=2
Exploit
http://marc.info/?l=full-disclosure&m=123998062108561&w=2
Exploit
http://razorcms.co.uk/support/viewtopic.php?f=13&t=325
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/34566
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/50358