Sploitus

CVE-2007-0882

13 known exploits for CVE-2007-0882

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Affected products
Solaris
Oracle Solaris
= 10, 11
Sun Sunos
= 5.10, 5.11
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
97.8% (100th percentile)
Weakness
CWE-88
NVD status
Modified
Published
2007-02-12
CVE-2007-0882 at NVD
Authoritative description, scoring and affected products

13 known exploits for CVE-2007-0882

Proof-of-concept code and exploit modules indexed by Sploitus