CVE-2009-4211
Last modified
CVE-2009-4211 is a vulnerability of currently unknown severity. The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.. EPSS estimates a 1.69% chance of exploitation in the next 30 days.
Description
The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Disa | Srr For Solaris | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4211?
How severe is CVE-2009-4211?
How do I fix CVE-2009-4211?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4205Directory traversal vulnerability in admin.php in Flashlight…
- CVE-2009-4206SQL injection vulnerability in admin.link.modify.php in Mill…
- CVE-2009-4207Cross-site scripting (XSS) vulnerability in the Webform modu…
- CVE-2009-4208SQL injection vulnerability in the os_news module in Open-sc…
- CVE-2009-4209Multiple cross-site scripting (XSS) vulnerabilities in admin…
- CVE-2009-4210The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP…
- CVE-2009-4212Multiple integer underflows in the (1) AES and (2) RC4 decry…
- CVE-2009-4214Cross-site scripting (XSS) vulnerability in the strip_tags f…
- CVE-2009-4215Panda Global Protection 2010, Internet Security 2010, and An…
- CVE-2009-4216Directory traversal vulnerability in funzioni/lib/menulast.p…
- CVE-2009-4217SQL injection vulnerability in the Itamar Elharar MusicGalle…
- CVE-2009-4218Multiple SQL injection vulnerabilities in files/login.asp in…
Are you affected by CVE-2009-4211?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
