CVE-2003-0027

SUN Solaris - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/sunrpc/solaris_kcms_readfile.rb

Scores

EPSS 0.6515
EPSS Percentile 98.5%

Details

Status published
Products (9)
sun/solaris 2.5.1
sun/solaris 2.6
sun/solaris 7.0
sun/solaris 8.0
sun/solaris 9.0 (2 CPE variants)
sun/sunos
sun/sunos 5.5.1
sun/sunos 5.7
sun/sunos 5.8
Published Feb 07, 2003
Tracked Since Feb 18, 2026