Description
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.5.3)
WordPress Plugin Ivory Search-WordPress Search Cross-Site Scripting (4.6)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0165)
WordPress Plugin Custom Dashboard & Login Page-AGCA Cross-Site Request Forgery (6.5.4)