Vulnerability Name: | CCN-1434 | ||||||
Published: | 1998-04-07 | ||||||
Updated: | 1998-04-07 | ||||||
Summary: | The IRIX Performer API Search Tool (pdfdispaly.cgi) is a Web-based search tool that assists in the searching of man pages, documents, example code, and special items known as classes, methods, tokens, and samples. A vulnerability in the pfdispaly.cgi program could allow a remote user to run any file on the system with 'nobody' privileges.
This vulnerability was not corrected in the SGI pfdispaly patch 3018. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue, 7 Apr 1998 03:16:01 +0200 perfomer_tools again Source: XF Type: UNKNOWN sgi-dispaly-patch-vuln(1434) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |