CVE-2006-5852
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.
- Affected products
- Openbase Sql
- Openbase International Ltd Openbase
- = 7.0.15, 8.0.4, 9.1.5, 10.0
- Fix
- Available
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 0.8% (52th percentile)
- NVD status
- Modified
- Published
- 2006-11-10
CVE-2006-5852 at NVD
1 known exploit for CVE-2006-5852
Proof-of-concept code and exploit modules indexed by Sploitus