The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-05-17T04:00:00

Updated: 2024-08-07T21:44:06.142Z

Reserved: 2005-04-27T00:00:00

Link: CVE-2005-1307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-05-17T04:00:00.000

Modified: 2017-07-11T01:32:36.890

Link: CVE-2005-1307

cve-icon Redhat

No data.