CVE-2007-6210
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.8%
from disclosure to weapon0 days
Published on NVDDec 4
1st PoCDec 3
exploitation probability
0.8%top 48% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/30839⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=452682http://secunia.com/advisories/27903http://secunia.com/advisories/27948http://secunia.com/advisories/27978https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00196.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00232.htmlhttp://www.debian.org/security/2007/dsa-1420http://www.securityfocus.com/bid/26680http://www.zabbix.com/forum/showthread.php?t=8400