A100900-1Vendor advisory
http://www.atstake.com/research/advisories/2000/a100900-1.txt CVE-2000-1072
Netscape iCal 2.1 Patch2 - iPlanet iCal 'iplncal.sh' Permissions
Record summary
CVE-2000-1072 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNetscape iCal 2.1 Patch2 - iPlanet iCal 'iplncal.sh' PermissionsExploitDB exploitby @stakeNot analyzed1 file
References
57212vdb entry
http://www.osvdb.org/7212 1768vdb entry
http://www.securityfocus.com/bid/1768 ical-iplncal-gain-access(5756)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5756 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1072