Record summary

CVE-2003-1167 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBkpopup 0.9.x - Privileged Command ExecutionExploitDB exploitby b0fNot analyzed1 file
ExploitDB

PoC details

References

6