Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4885

Опубликовано: 26 окт. 2013
Источник: debian
EPSS Низкий

Описание

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nmapfixed6.40-0.1package
nmapnot-affectedsqueezepackage
nmapfixed6.00-0.3+deb7u1wheezypackage

EPSS

Процентиль: 91%
0.06429
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

redhat
больше 12 лет назад

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

nvd
больше 12 лет назад

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

github
больше 3 лет назад

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

EPSS

Процентиль: 91%
0.06429
Низкий