Record summary

CVE-2002-0793 has a selected CVSS score of 5.5 (medium); EIP currently links 3 catalogued exploits.

Description

Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBQNX RTOS 4.25 - 'CRTTrap' File DisclosureExploitDB exploitby Simon OuelletteNot analyzed1 file
ExploitDB

PoC details
ExploitDBQNX RTOS 4.25 - monitor Arbitrary File ModificationExploitDB exploitby Simon OuelletteNot analyzed1 file
ExploitDB

PoC details
ExploitDBQNX RTOS 4.25 - dumper Arbitrary File ModificationExploitDB exploitby Simon OuelletteNot analyzed1 file
ExploitDB

PoC details

References

10