CVE Database
/

CVE-2011-4338

Back to search

CVE-2011-4338

Published: Feb 12, 2020

Modified: Aug 7, 2024

PUBLISHED

Description

Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.

VendorProductVersions

shaman

shaman

affected
1.0.9

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now