[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252271

 
 

909

 
 

196835

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-4387Date: (C)2006-10-03   (M)2023-12-22


Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1016955
BID-20271
SECUNIA-22187
OSVDB-29273
ADV-2006-3852
APPLE-SA-2006-09-29
macos-webobjects-incorrect-privileges(29296)

CPE    8
cpe:/o:apple:mac_os_x:10.4
cpe:/o:apple:mac_os_x:10.4.5
cpe:/o:apple:mac_os_x:10.4.4
cpe:/o:apple:mac_os_x:10.4.7
...

© SecPod Technologies