Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-3842

Опубликовано: 28 окт. 2010
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:curl:curl:7.20.0:*:*:*:*:*:*:*
cpe:2.3:a:curl:curl:7.20.1:*:*:*:*:*:*:*
cpe:2.3:a:curl:curl:7.21.1:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00898
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 15 лет назад

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

debian
больше 15 лет назад

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, w ...

github
больше 3 лет назад

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

EPSS

Процентиль: 75%
0.00898
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-22