ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/04/08/3 | mailing list third party advisory exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74739 | third party advisory vdb entry |
http://www.openwall.com/lists/oss-security/2012/04/09/4 | third party advisory mailing list |
https://www.securityfocus.com/bid/52936 | third party advisory vdb entry |