vendor:
TerminatorX
by:
m00 Security / Over_G
7.5
CVSS
HIGH
Multiple vulnerabilities when handling command-line and environment variable data
N/A
CWE
Product Name: TerminatorX
Affected Version From: 3.8
Affected Version To: 3.8
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
TerminatorX v3.80 – local root exploit
It has been reported that TerminatorX may be prone to multiple vulnerabilities when handling command-line and environment variable data. As a result, an attacker may be capable of exploiting the application in a variety of ways to execute arbitrary code with elevated privileges. It should be noted that TerminatorX is not installed setuid by default, however the author recommends that users make the application setuid root.
Mitigation:
Make the application setuid root.