CVE Vulnerabilities

CVE-2009-1462

Published: Apr 28, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.

Affected Software

Name Vendor Start Version End Version
Razorcms Razorcms * 0.3 (including)
Razorcms Razorcms 0.2 (including) 0.2 (including)
Razorcms Razorcms 0.3-rc2 (including) 0.3-rc2 (including)

References