Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-2725

Опубликовано: 04 фев. 2014
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kde:ark:*:*:*:*:*:*:*:*
Версия до 2.17 (включая)
cpe:2.3:a:kde:kde_sc:*:*:*:*:*:*:*:*
Версия до 4.7.4 (включая)
cpe:2.3:a:kde:kde_sc:4.7.0:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.7.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.7.3:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02952
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 12 лет назад

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

redhat
около 15 лет назад

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

debian
больше 12 лет назад

Directory traversal vulnerability in Ark 4.7.x and earlier allows remo ...

github
около 4 лет назад

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

EPSS

Процентиль: 86%
0.02952
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-22