CVE-2007-1370
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/03/2007
Last modified:
09/04/2025
Description
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.
Impact
Base Score 2.0
6.20
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zend:zend_platform:2.2.1a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zend:zend_platform:2.2.1a:a:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/24501
- http://www.osvdb.org/32772
- http://www.php-security.org/MOPB/BONUS-06-2007.html
- http://www.securityfocus.com/bid/22801
- http://www.vupen.com/english/advisories/2007/0829
- http://www.zend.com/products/zend_platform/security_vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32825
- http://secunia.com/advisories/24501
- http://www.osvdb.org/32772
- http://www.php-security.org/MOPB/BONUS-06-2007.html
- http://www.securityfocus.com/bid/22801
- http://www.vupen.com/english/advisories/2007/0829
- http://www.zend.com/products/zend_platform/security_vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32825



