Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious "make" program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ChangePassword 权限提升漏洞
Vulnerability Description
ChangePassword是一个基于Web的密码管理系统。 ChangePassword 0.8存在本地权限提升漏洞。 在通过changepassword.cgi在安装配置setuid时,本地用户可通过修改PATH环境变量,指向恶意的"make" 程序,从而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A