Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwfv-5xmw-xx69

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

EPSS

Процентиль: 75%
0.00898
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 15 лет назад

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

nvd
больше 15 лет назад

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

debian
больше 15 лет назад

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, w ...

EPSS

Процентиль: 75%
0.00898
Низкий

Дефекты

CWE-22