Exploitation Summary
EIP tracks 2 public exploits for CVE-2000-0935. PoCs published by Optyx.
AI-analyzed exploit summary This exploit leverages a symlink vulnerability in Samba SWAT's logging mechanism to overwrite arbitrary files, specifically targeting /etc/passwd to add a root user. It requires local access and SWAT with CGI logging enabled.
Description
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.
Exploits (2)
This exploit leverages a symlink vulnerability in Samba SWAT's logging mechanism to overwrite arbitrary files, specifically targeting /etc/passwd to add a root user. It requires local access and SWAT with CGI logging enabled.
This exploit leverages a symlink vulnerability in Samba SWAT's logging mechanism to overwrite /etc/passwd, enabling local privilege escalation to root. It creates a malicious user entry and restores the original passwd file after exploitation.