Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10916

Опубликовано: 01 авг. 2018
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
CVSS2: 7.8
EPSS Низкий

Описание

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lftp_project:lftp:*:*:*:*:*:*:*:*
Версия до 4.8.3 (включая)
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
Конфигурация 3
cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00696
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

7.8 High

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
redhat
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
debian
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 doe ...

suse-cvrf
почти 7 лет назад

Security update for lftp

suse-cvrf
почти 7 лет назад

Security update for lftp

EPSS

Процентиль: 71%
0.00696
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

7.8 High

CVSS2

Дефекты

CWE-20
CWE-20