PoC Index

CVE-2004-1161

HIGH 7.5EPSS 7.3%

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
7.33% chance of exploitation in the next 30 days, 94th percentile
Published
2004-12-10
Updated
2024-08-08

ExploitDB entries (1)

References

Related