CVE-2002-0887
scoadmin - Caldera/SCO OpenServer <5.0.6 - Local Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0887. PoCs published by Kevin Finisterre.
AI-analyzed exploit summary This exploit leverages a predictable temporary file naming vulnerability in the scoadmin utility to overwrite arbitrary files via symbolic link manipulation. The attacker creates a symlink to a target file (e.g., /etc/passwd) in the expected temporary file location, which scoadmin follows and overwrites.
Description
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.
Exploits (1)
This exploit leverages a predictable temporary file naming vulnerability in the scoadmin utility to overwrite arbitrary files via symbolic link manipulation. The attacker creates a symlink to a target file (e.g., /etc/passwd) in the expected temporary file location, which scoadmin follows and overwrites.