Title : AOL "America Online 9.0" Insecure Directory Permissions and File Manipulation Vulnerability VUPEN ID : VUPEN/ADV-2006-3317 CVE ID : CVE-2006-0948
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-18
Technical Description
A vulnerability has been identified in AOL, which could be exploited by local attackers to obtain elevated privileges. This flaw is due to insecure permissions being set on the "America Online x.0" directory (Everyone/Full Control), which could be exploited by malicious users to delete certain files or replace them with malicious binaries that will be executed with elevated privileges.