CVE-2000-1072
iPlanet iCal 2.1 Patch 2 - Arbitrary Command Execution via World-Writable Files
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-1072. PoCs published by @stake.
AI-analyzed exploit summary This exploit leverages a world-writable script in iPlanet iCal to gain root privileges. It first obtains an icsuser shell by modifying a startup script, then creates a shim library to execute arbitrary code as root when the service restarts.
Description
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.
Exploits (1)
This exploit leverages a world-writable script in iPlanet iCal to gain root privileges. It first obtains an icsuser shell by modifying a startup script, then creates a shim library to execute arbitrary code as root when the service restarts.