漏洞标题
N/A
漏洞描述信息
**争议** WampServer 3.0.6 有两个名为 'wampmanager.exe' 和 'unins000.exe' 的文件,其中 'wampmanager.exe' 和 'unins000.exe' 的 ACL 用于修改。这可能会导致有授权但非特权的本地用户在系统中执行任意代码并拥有更高级别的权限。要正确利用这个漏洞,本地攻击者必须插入一个名为 wampmanager.exe 或 unins000.exe 的可执行文件,并替换原始文件。下次一个更高特权的用户启动其中一个程序时,本地攻击者选择的恶意代码将运行。注意:供应商否认这份报告的相关性,认为一个配置中“‘有人’(攻击者)能够替换 PC 上的文件”并不是 WampServer 的过失。
CVSS信息
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called wampmanager.exe or unins000.exe and replace the original files. The next time one of these programs is launched by a more privileged user, malicious code chosen by the local attacker will run. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
WampServer 安全漏洞
漏洞描述信息
WampServer是一套用于Windows平台的Apache、Mysql和PHP集成安装环境。 WampServer 3.0.6版本中的wampmanager.exe和unins000.exe文件存在安全漏洞。本地攻击者可将wampmanager.exe可执行文件或unins000.exe可执行文件替换源文件利用该漏洞以系统上提升的权限执行任意代码,。
CVSS信息
N/A
漏洞类别
授权问题