HIGH · 7.2

CVE-2006-0948

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain pri...

Vulnerability Description

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AolAol9.0_4184.2340

References

FAQ

What is CVE-2006-0948?

CVE-2006-0948 is a vulnerability with a CVSS score of 7.2 (HIGH). AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain pri...

How severe is CVE-2006-0948?

CVE-2006-0948 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0948?

Check the references section above for vendor advisories and patch information. Affected products include: Aol Aol.