Untrusted search path vulnerability in hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via a modified PATH environment variable, which is used during execution of the (1) route, (2) mv, and (3) cp programs, a different vulnerability than CVE-2010-1671.
References
Configurations
Information
Published : 2010-08-02 14:00
Updated : 2017-08-16 18:32
NVD link : CVE-2010-2929
Mitre link : CVE-2010-2929
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
pharscape
- hsolink