EIP-2026-103817
PRE-CVESun iPlanet Messaging Server 5.2 HotFix 1.16 - Root Password Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103817. PoCs published by php0t.
AI-analyzed exploit summary The exploit demonstrates a symlink attack against iPlanet Messaging Server's setuid binary `pipe_master`, which reads the first line of any file as root due to improper handling of the `CONFIGROOT` environment variable. The PoC shows how to leak the first line of `/etc/shadow` by symlinking `msg.conf` to it.
Description
Sun iPlanet Messaging Server 5.2 HotFix 1.16 - Root Password Disclosure
Exploits (1)
The exploit demonstrates a symlink attack against iPlanet Messaging Server's setuid binary `pipe_master`, which reads the first line of any file as root due to improper handling of the `CONFIGROOT` environment variable. The PoC shows how to leak the first line of `/etc/shadow` by symlinking `msg.conf` to it.