CVE-2007-0882

Solaris 10-11 - Command Injection

Title source: llm

Description

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Exploits (4)

exploitdb WORKING POC VERIFIED
by kingcope · bashremotesolaris
https://www.exploit-db.com/exploits/3293
metasploit WORKING POC EXCELLENT
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/solaris/telnet/fuser.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotesolaris
https://www.exploit-db.com/exploits/16328
exploitdb WORKING POC VERIFIED
by MC · rubyremotesolaris
https://www.exploit-db.com/exploits/9918

References (19)

Scores

EPSS 0.9096
EPSS Percentile 99.6%

Classification

CWE
CWE-88
Status draft

Affected Products (4)

oracle/solaris
oracle/solaris
sun/sunos
sun/sunos

Timeline

Published Feb 12, 2007
Tracked Since Feb 18, 2026