Untrusted search path vulnerability in Explzh 5.67 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000043.html | vdb entry third party advisory |
http://jvn.jp/en/jp/JVN85599999/index.html | vdb entry third party advisory |
http://www.ponsoftware.com/en/ | vendor advisory |