CVE-2005-2807
frox 0.7.18 - Unauthenticated Arbitrary File Read via Configuration File Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2807. PoCs published by rotor.
AI-analyzed exploit summary This exploit demonstrates a file read vulnerability in Frox by passing an arbitrary file path as an argument, causing the application to disclose its contents. The issue is exploitable only if Frox is installed with setuid or setgid privileges.
Description
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
Exploits (1)
This exploit demonstrates a file read vulnerability in Frox by passing an arbitrary file path as an argument, causing the application to disclose its contents. The issue is exploitable only if Frox is installed with setuid or setgid privileges.