Exploit SGI IRIX 5.1/5.2 - 'sgihelp' Local Privilege Escalation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
19354
Проверка EDB
  1. Пройдено
Автор
ANONYMOUS
Тип уязвимости
LOCAL
Платформа
AIX
CVE
cve-1999-1219
Дата публикации
1996-12-02
SGI IRIX 5.1/5.2 - 'sgihelp' Local Privilege Escalation
Код:
source: https://www.securityfocus.com/bid/468/info

The sgihelp program, from SGI and included with IRIX 5.1 and 5.2, contains a vulnerability. sgihelp contains an option that allows a user to print to a command. Certain SGI utilities, including PrintStatus, printers, scanners, and a number of others, will call this program without changing their uid to the users, from roots. As such, arbitrary commands can be executed as root using the 'print to command' option of sgihelp.

Run PrintStatus
Press the 'help' button.
Select the 'print to command' option. This will allow you to execute anything as root.
 
Источник
www.exploit-db.com

Похожие темы