CVE-2005-1307
HIGH 7.2EPSS 3.7%
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 3.65% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2005-05-17
- Updated
- 2024-08-07
Proof-of-concept exploits (2)
- http://archives.neohapsis.com/archives/bugtraq/2004-12/0040.html
- http://marc.info/?l=bugtraq&m=111627622403544&w=2