CVE Vulnerabilities

CVE-2009-1462

Published: Apr 28, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.

Affected Software

NameVendorStart VersionEnd Version
RazorcmsRazorcms*0.3 (including)
RazorcmsRazorcms0.2 (including)0.2 (including)
RazorcmsRazorcms0.3-rc2 (including)0.3-rc2 (including)

References