CVE-2008-0310

SCO UnixWare 7.1.4 - Local Path Traversal via PKGINST Environment Variable

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0310. PoCs published by qaaz.

AI-analyzed exploit summary This exploit leverages a vulnerability in SCO UnixWare's pkgadd utility to perform a local privilege escalation by manipulating symbolic links and the sulog file. It abuses improper handling of the PKGINST variable to overwrite the su configuration file, granting root access.

Description

Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.

Exploits (1)

exploitdb WORKING POC VERIFIED
by qaaz · bashlocalsco
https://www.exploit-db.com/exploits/5355

This exploit leverages a vulnerability in SCO UnixWare's pkgadd utility to perform a local privilege escalation by manipulating symbolic links and the sulog file. It abuses improper handling of the PKGINST variable to overwrite the su configuration file, granting root access.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: SCO UnixWare < 7.1.4 p534589
Auth required
Prerequisites: Local user access on the target system · Presence of vulnerable pkgadd utility
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.sco.com/support/update/download/release.php?rid=324
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019787
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41759
Various Sources vendor-advisory x_refsource_sco
http://ftp.sco.com/pub/unixware7/714/security/p534589/p534589.txt
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5355
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=676
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29657

Scores

EPSS 0.0101
EPSS Percentile 58.5%

Details

CWE
CWE-22
Status published
Products (1)
sco/unixware 7.1.4
Published Apr 07, 2008
Tracked Since Feb 18, 2026