CVE-2006-5851

openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/output file, a different vulnerability than CVE-2006-5328.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openbase_international_ltd:openbase:7.0.15:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:openbase_international_ltd:openbase:8.0.4:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:openbase_international_ltd:openbase:9.1.5:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:openbase_international_ltd:openbase:10.0:*:mac_os_x:*:*:*:*:*

History

21 Nov 2024, 00:20

Type Values Removed Values Added
References () http://marc.info/?l=full-disclosure&m=116296717330758&w=2 - Mailing List () http://marc.info/?l=full-disclosure&m=116296717330758&w=2 - Mailing List
References () http://secunia.com/advisories/22742 - Vendor Advisory () http://secunia.com/advisories/22742 - Vendor Advisory
References () http://www.digitalmunition.com/DMA%5B2006-1107a%5D.txt - Exploit () http://www.digitalmunition.com/DMA%5B2006-1107a%5D.txt - Exploit
References () http://www.vupen.com/english/advisories/2006/4404 - Not Applicable () http://www.vupen.com/english/advisories/2006/4404 - Not Applicable
References () https://www.exploit-db.com/exploits/2737 - () https://www.exploit-db.com/exploits/2737 -

Information

Published : 2006-11-10 02:07

Updated : 2024-11-21 00:20


NVD link : CVE-2006-5851

Mitre link : CVE-2006-5851

CVE.ORG link : CVE-2006-5851


JSON object : View

Products Affected

openbase_international_ltd

  • openbase
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')