Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-2473 | First vendor Publication | 2004-12-31 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:H/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 1.2 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | High |
Cvss Expoit Score | 1.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2473 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
12118 | wmFrog Insecure Temporary File Creation xmFrot contains a flaw that may allow a malicious local user to perform certain actions with escalated privileges. The issue is caused by temporary files being created insecurely by default which can be exploited via symlink attacks. It is possible that the flaw may allow an attacker to create or overwrite arbitrary files with privileges of the user running wmFrog resulting in a loss of integrity. |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:45 |
|
2024-11-28 12:06:32 |
|
2021-05-04 12:02:38 |
|
2021-04-22 01:02:50 |
|
2020-05-23 00:16:11 |
|
2017-07-11 12:01:44 |
|
2016-06-28 15:11:46 |
|
2016-04-26 13:09:58 |
|
2013-05-11 11:49:13 |
|