CVE-2002-0311

UnixWare 7.1.1-Open UNIX 8.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0311. PoCs published by jGgM.

AI-analyzed exploit summary This exploit targets a command injection vulnerability in UnixWare's scoadminreg.cgi by passing a malicious payload via the -c option. It compiles a C program to set SUID/SGID on a shell, then executes it via the vulnerable CGI script to gain root privileges.

Description

Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

Exploits (1)

exploitdb WORKING POC VERIFIED
by jGgM · bashlocalunixware
https://www.exploit-db.com/exploits/21239

This exploit targets a command injection vulnerability in UnixWare's scoadminreg.cgi by passing a malicious payload via the -c option. It compiles a C program to set SUID/SGID on a shell, then executes it via the vulnerable CGI script to gain root privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: UnixWare scoadminreg.cgi
No auth needed
Prerequisites: Presence of vulnerable scoadminreg.cgi at /opt/webtop/bin/i3un0212/cgi-bin/admin/ · Write access to /tmp directory · GCC compiler available
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7977.php
Exploit mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/251747
Various Sources vendor-advisory x_refsource_caldera
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.6/CSSA-2002-SCO.6.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3936

Scores

EPSS 0.0454
EPSS Percentile 90.3%

Details

Status published
Products (2)
caldera/openunix 8.0
caldera/unixware 7.1.1
Published May 31, 2002
Tracked Since Feb 18, 2026