CVE Vulnerabilities

CVE-2014-7180

Published: Oct 25, 2014 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.

Affected Software

Name Vendor Start Version End Version
Electriccommander Electric_cloud 5.0.0 5.0.0
Electriccommander Electric_cloud * 4.2.5
Electriccommander Electric_cloud 5.0.1 5.0.1
Electriccommander Electric_cloud 5.0.2 5.0.2

References