CVE-2007-5804
Last modified
CVE-2007-5804 is a vulnerability of currently unknown severity. cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Aix | 5.2 |
| Ibm | Aix | 5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5804?
How severe is CVE-2007-5804?
How do I fix CVE-2007-5804?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5798Multiple cross-site scripting (XSS) vulnerabilities in uddig…
- CVE-2007-5799Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2007-5800Multiple PHP remote file inclusion vulnerabilities in the Ba…
- CVE-2007-5801Unspecified vulnerability in WORK system e-commerce before 4…
- CVE-2007-5802Directory traversal vulnerability in index.php in Firewolf T…
- CVE-2007-5803Multiple cross-site scripting (XSS) vulnerabilities in CGI p…
- CVE-2007-5805cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the…
- CVE-2007-5806Cross-site scripting (XSS) vulnerability in Services/Utiliti…
- CVE-2007-5807Buffer overflow in the register function in Ultra Star Reade…
- CVE-2007-5808Unspecified vulnerability in the Groupmax Collaboration - Sc…
- CVE-2007-5809Cross-site scripting (XSS) vulnerability in Hitachi Web Serv…
- CVE-2007-5810Hitachi Web Server 01-00 through 03-00-01, as used by certai…
Are you affected by CVE-2007-5804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
