CVE-2004-0390

SCO OpenServer <5.0.8 - Auth Bypass

Title source: llm
STIX 2.1

Description

SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Richard Johnson · textlocalsco
https://www.exploit-db.com/exploits/20851

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16113
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html
Third Party Advisory, VDB Entry vendor-advisory x_refsource_sco
http://www.securityfocus.com/advisories/6684

Scores

EPSS 0.0336
EPSS Percentile 87.5%

Details

Status published
Products (3)
sco/openserver 5.0.5
sco/openserver 5.0.6
sco/openserver 5.0.7
Published Dec 31, 2004
Tracked Since Feb 18, 2026