Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).
References
Configurations
History
20 Nov 2024, 23:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/231705 - Third Party Advisory, US Government Resource | |
References | () http://www.kb.cert.org/vuls/id/609137 - Third Party Advisory, US Government Resource | |
References | () http://www.kb.cert.org/vuls/id/CRDY-5EXQRP - Third Party Advisory, US Government Resource | |
References | () http://www.kb.cert.org/vuls/id/CRDY-5EXQSV - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/7475 - Patch | |
References | () http://www.securityfocus.com/bid/7477 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/11920 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/11921 - |
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:46
NVD link : CVE-2003-1121
Mitre link : CVE-2003-1121
CVE.ORG link : CVE-2003-1121
JSON object : View
Products Affected
scriptlogic
- scriptlogic
CWE