CVE

Id
9691  
CVE No.
CVE-2004-1263  
Status
Candidate  
Description
changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious "make" program.  
Phase
Assigned (20041220)  
Votes
None (candidate not yet proposed)  
Comments