Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Electriccommander | Electric_cloud | * | 4.2.5 (including) |
Electriccommander | Electric_cloud | 5.0.0 (including) | 5.0.0 (including) |
Electriccommander | Electric_cloud | 5.0.1 (including) | 5.0.1 (including) |
Electriccommander | Electric_cloud | 5.0.2 (including) | 5.0.2 (including) |