Privilege Escalation via Symlink Attack in Zarafa Collaboration Platform (ZCP)

Privilege Escalation via Symlink Attack in Zarafa Collaboration Platform (ZCP)

CVE-2015-6566 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.

Learn more about our User Device Pen Test.