Babelweb 'user' Option Local Privilege Escalation Weakness
BID:49363
Info
Babelweb 'user' Option Local Privilege Escalation Weakness
| Bugtraq ID: | 49363 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 30 2011 12:00AM |
| Updated: | Aug 30 2011 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Gabriel Kerneis Babelweb 0.2.1 |
| Not Vulnerable: |
Gabriel Kerneis Babelweb 0.2.2 |
Discussion
Babelweb 'user' Option Local Privilege Escalation Weakness
Babelweb is prone to a local privilege-escalation weakness.
Attackers can use this weakness to exploit other latent vulnerabilities in the application and to execute code with root privileges. This may result in the complete compromise of an affected computer.
Babelweb 0.2.1 is vulnerable; other versions may also be affected.
Babelweb is prone to a local privilege-escalation weakness.
Attackers can use this weakness to exploit other latent vulnerabilities in the application and to execute code with root privileges. This may result in the complete compromise of an affected computer.
Babelweb 0.2.1 is vulnerable; other versions may also be affected.
Exploit / POC
Babelweb 'user' Option Local Privilege Escalation Weakness
Attackers must first locate a latent vulnerability in the application and can then use readily available commands to exploit this weakness.
Attackers must first locate a latent vulnerability in the application and can then use readily available commands to exploit this weakness.
Solution / Fix
Babelweb 'user' Option Local Privilege Escalation Weakness
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Babelweb 'user' Option Local Privilege Escalation Weakness
References:
References:
- GIT Commit (kerneis)
- Product Homepage (Gabriel Kerneis)