Record summary

CVE-2000-1072 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBNetscape iCal 2.1 Patch2 - iPlanet iCal 'iplncal.sh' PermissionsExploitDB exploitby @stakeNot analyzed1 file
ExploitDB

PoC details

References

5