vendor:
webapp-config
by:
Eric Romang
7.2
CVSS
HIGH
Insecure File Creation
22
CWE
Product Name: webapp-config
Affected Version From: < webapp-config 1.10-r14
Affected Version To: < webapp-config 1.10-r14
Patch Exists: Yes
Related CWE: N/A
CPE: a:gentoo:webapp-config
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2005
Gentoo webapp-config Insecure File Creation Vulnerability
Gentoo webapp-config is prone to an insecure file creation vulnerability. This issue is due to a design error that causes the application to fail to verify the existence of a file before writing to it. An attacker may leverage this issue to cause arbitrary shell commands to be executed with superuser privileges.
Mitigation:
Upgrade to the latest version of webapp-config.