CVE-2007-1588
N/A
N/A
Summary
server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote attackers to execute CGI programs with unintended privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://osvdb.org/34521
- http://www.myserverproject.net/news.php
- http://sourceforge.net/mailarchive/forum.php?thread_id=31631045&forum_id=47875
References
- http://osvdb.org/34521
- http://www.myserverproject.net/news.php
- http://sourceforge.net/mailarchive/forum.php?thread_id=31631045&forum_id=47875
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.