Zend Platform Insecure File Permission Vulnerability
BID:22801
Info
Zend Platform Insecure File Permission Vulnerability
| Bugtraq ID: | 22801 |
| Class: | Configuration Error |
| CVE: |
CVE-2007-1370 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 03 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | Discovery is credited to Stefan Esser. |
| Vulnerable: |
Zend Zend Platform 2.2.1 Zend Zend Platform 2.2.1a Zend Zend Platform 2.2.1(a) |
| Not Vulnerable: |
Zend Zend Platform 3.0 |
Discussion
Zend Platform Insecure File Permission Vulnerability
Files that are installed with the Zend Platform have insecure default permissions. This files include scripts and executables that will be run when the application is started. This could let local attackers elevate their privileges.
Files that are installed with the Zend Platform have insecure default permissions. This files include scripts and executables that will be run when the application is started. This could let local attackers elevate their privileges.
Exploit / POC
Zend Platform Insecure File Permission Vulnerability
Attackers can exploit this vulnerability by altering or replacing one of the affected files.
Attackers can exploit this vulnerability by altering or replacing one of the affected files.
Solution / Fix
Zend Platform Insecure File Permission Vulnerability
Solution:
This issue has been addressed in Zend Platform 3.0.
Solution:
This issue has been addressed in Zend Platform 3.0.
References
Zend Platform Insecure File Permission Vulnerability
References:
References: