vendor:
iPlanet Messaging Server
by:
None
7,5
CVSS
HIGH
Symlink Attack
59
CWE
Product Name: iPlanet Messaging Server
Affected Version From: 5.2 HotFix 1.16
Affected Version To: 5.2 HotFix 1.16
Patch Exists: NO
Related CWE: None
CPE: a:sun_microsystems:iplanet_messaging_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris
2006
iPlanet Messaging Server 5.2 HotFix 1.16 Symlink Attack
A symlink attack is possible, and as a result it is possible to read the first line of any file with uid=0.
Mitigation:
Ensure that the CONFIGROOT environment variable is not set.