mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
920 B
920 B
CVE-2016-5847
Description
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
POC
Reference
- http://packetstormsecurity.com/files/138284/SAP-CAR-Archive-Tool-Denial-Of-Service-Security-Bypass.html
- http://seclists.org/fulldisclosure/2016/Aug/46
- https://www.coresecurity.com/advisories/sap-car-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/40230/