vendor:
by:
bannedit
5.5
CVSS
MEDIUM
File Append
73
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
sing file append exploit
This exploit adds an account to the machine by appending a file using logrotate. It relies on logrotate for help and can be modified to work with cron daemons that are not too strict about the cron file format.
Mitigation:
Remove or secure the vulnerable file or fix the logrotate configuration to prevent unauthorized file append.