CVE-2012-10022 describes a local privilege escalation vulnerability in Kloxo versions 6.1.12 and earlier. Two setuid root binaries, lxsuexec and lxrestart, allow users with Apache-level access (uid 48) to execute arbitrary commands as root without authentication. This flaw carries a CVSS score of 8.5 (HIGH), indicating a severe risk with low attack complexity and high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Metasploit module exists for this vulnerability, suggesting readily available exploit code. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| LxCenter | Kloxo | >= 0, <= 6.1.12CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.