CVE-2005-2725
QNX RTOS 6.1.0 and 6.3 - Arbitrary File Read via inputtrap Utility
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2725. PoCs published by Julio Cesar Fort.
AI-analyzed exploit summary The exploit leverages a local arbitrary file disclosure vulnerability in QNX RTOS due to improper access control in the 'inputtrap' utility. By executing 'inputtrap -t /etc/shadow start', a local attacker can read arbitrary files with superuser privileges.
Description
The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.
Exploits (1)
The exploit leverages a local arbitrary file disclosure vulnerability in QNX RTOS due to improper access control in the 'inputtrap' utility. By executing 'inputtrap -t /etc/shadow start', a local attacker can read arbitrary files with superuser privileges.