CVE-2015-0974

Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediaplayerdll.dll.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mobilis:mobiconnect:1.0.0b03:*:*:*:*:*:*:*

History

21 Nov 2024, 02:24

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/129808/ZTE-Datacard-MF19-Privilege-Escalation-DLL-Hijacking.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/129808/ZTE-Datacard-MF19-Privilege-Escalation-DLL-Hijacking.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2017-08-28 15:29

Updated : 2024-11-21 02:24


NVD link : CVE-2015-0974

Mitre link : CVE-2015-0974

CVE.ORG link : CVE-2015-0974


JSON object : View

Products Affected

mobilis

  • mobiconnect
CWE
CWE-426

Untrusted Search Path