CVE-2002-0311 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 4.5% (pctl 91)
Patch early
A public exploit exists.
Description
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 4.54% — more likely to be exploited than 91% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-05-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| caldera | openunix |
| caldera | unixware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Caldera UnixWare 7.1.1 - WebTop 'SCOAdminReg.cgi' Arbitrary Command Execution | 2002-01-20 |
References
- ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.6/CSSA-2002-SCO.6.txt
- http://online.securityfocus.com/archive/1/251747
- http://www.iss.net/security_center/static/7977.php
- http://www.securityfocus.com/bid/3936
- ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.6/CSSA-2002-SCO.6.txt
- http://online.securityfocus.com/archive/1/251747
- http://www.iss.net/security_center/static/7977.php
- http://www.securityfocus.com/bid/3936
→ the Explorer · watch your stack · NVD