Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%\Quest Shared directory, which allows local users to gain privileges via a Trojan horse file.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/secunia_research/2012-13/ | vendor advisory |
http://secunia.com/advisories/48663 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75192 | vdb entry |
http://www.securityfocus.com/bid/53276 | vdb entry |