4.6

CVE-2014-7180

Exploit
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.361
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://docs.electric-cloud.com/commander_doc/5_0_3/HTML5/ReleaseNotes/commander_releasenotes.htm
Vendor Advisory
http://packetstormsecurity.com/files/128819/ElectricCommander-4.2.4.71224-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2014/Oct/104
http://www.secureworks.com/advisories/SWRX-2014-010/SWRX-2014-010.pdf
Exploit
http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2014-010/
http://www.securityfocus.com/bid/70722
https://exchange.xforce.ibmcloud.com/vulnerabilities/97735