CNCVE编号:CNCVE-20010366 CVE编号:CAN-2001-0366 安全级别:高 漏洞中文描述: SAP R/3 Web Application Server Demo 1.5以前的版本中的saposcol信任PATH环境变量来发现和执行扩展程序,这允许本地用户通过把Path修改成指向一个特洛伊木马扩展程序来获得root权限。 漏洞英文描述: saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program. 漏洞参考: BUGTRAQ:20010429 SAP R/3 Web Application Server Demo for Linux: root exploit URL:http://www.securityfocus.com/archive/1/180498 BID:2662 URL:http://www.securityfocus.com/bid/2662 系统类型:其他 漏洞类型:环境错误