ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/CRDY-5EXQT9 | us government resource |
http://www.kb.cert.org/vuls/id/813737 | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11922 | vdb entry |
http://www.securityfocus.com/bid/7476 | vdb entry patch |