Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2007-5804
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM AIX swcons本地用户权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM AIX是一款商业性质的UNIX操作系统。 AIX的swcons工具实现上存在漏洞,本地攻击者可能利用此漏洞提升权限。 多个AIX版本中所捆绑的swcons工具在使用-p选项时没有执行过滤检查,如果文件不存在的话就会创建文件。这种情况都会将文件转换到222模式,而该模式允许系统上的所有用户修改文件,可能导致以root权限执行任意指令。但在默认的配置中,必须拥有组ID system才能执行swcons。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2007-5804
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2007-5804
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2007-5804

No comments yet


Leave a comment