20010211 Security Hole in Microfocus Cobolmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html CVE-2001-0208
Micro Focus Cobol 4.1 - Arbitrary Command Execution
Record summary
CVE-2001-0208 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicro Focus Cobol 4.1 - Arbitrary Command ExecutionExploitDB exploitby Dixie FlatlineNot analyzed1 file
References
32359vdb entry
http://www.securityfocus.com/bid/2359 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0208