« Volver al listado

CVE-2010-2945

Estado: ModificadaMedia (6.9)—

The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2945",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-08-30T20:00:02.500",
  "references": [
    {
      "url": "http://secunia.com/advisories/41005",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://svn.berlios.de/viewvc/slim?view=revision&revision=171",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/08/19/8",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/08/20/10",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/41005",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.berlios.de/viewvc/slim?view=revision&revision=171",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/08/19/8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/08/20/10",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-16"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp."
    },
    {
      "lang": "es",
      "value": "La configuración por defecto de SLiM en versiones anteriores a la v1.3.2 coloca los caractéres ./ (punto barra) al inicio de la opción default_path, lo que permite a usuarios locales escalar privilegios a través de un troyano en el directorio de trabajo actual. Relacionado con slim.conf y cfg.cpp."
    }
  ],
  "lastModified": "2026-06-16T23:21:48.533",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "419353A7-5286-4CFD-ACD2-C719C8E637B7",
              "versionEndIncluding": "1.3.1"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F73F2D8-48B0-47FF-97D0-E25F587FA790"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C021359-21DB-4B51-BAA0-24EDA9B1B4EB"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E79356D-42D3-4798-8514-9D34BE5F132B"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F727B05F-578B-4380-AD22-E2A7EC42F2A1"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7334548-EED7-47E0-9171-1824F96852E5"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAE13BC5-0CA5-4BFD-94C0-2DB1A07F6FB5"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3FA6EE1-6C06-4D7D-8B7C-0035754E03DF"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53481D04-2BF7-4295-9AF6-D36C16C45F48"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "243B2DB1-F8D7-44AF-AB6C-1C9A0B958F8F"
            },
            {
              "criteria": "cpe:2.3:a:simone_rota:slim_simple_login_manager:1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6893FC98-7B50-494A-BE62-E3B27F44D572"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}