The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=full-disclosure&m=123990481506680&w=2 - Exploit | |
References | () http://marc.info/?l=full-disclosure&m=123998062108561&w=2 - Exploit | |
References | () http://razorcms.co.uk/support/viewtopic.php?f=13&t=325 - Exploit, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/34566 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/50358 - |
Information
Published : 2009-04-28 16:30
Updated : 2024-11-21 01:02
NVD link : CVE-2009-1462
Mitre link : CVE-2009-1462
CVE.ORG link : CVE-2009-1462
JSON object : View
Products Affected
razorcms
- razorcms
CWE
CWE-264
Permissions, Privileges, and Access Controls