![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2009-4606 |
Description: | South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.800159 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-4606 Bugtraq: 20091020 South River Technologies WebDrive Service Bad Security Descriptor Local Elevation Of Privileges (Google Search) http://www.securityfocus.com/archive/1/507323/100/0/threaded http://retrogod.altervista.org/9sg_south_river_priv.html http://osvdb.org/59080 http://secunia.com/advisories/37083 http://www.vupen.com/english/advisories/2009/2994 XForce ISS Database: webdrive-webdrive-privilege-escalation(53885) https://exchange.xforce.ibmcloud.com/vulnerabilities/53885 |