Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-1000

Опубликовано: 13 мая 2010
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kdenetworkNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=591631kdenetwork: improper sanitization of metalink attribute for downloading files

EPSS

Процентиль: 89%
0.03849
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

nvd
около 16 лет назад

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

debian
около 16 лет назад

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4. ...

github
больше 4 лет назад

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

EPSS

Процентиль: 89%
0.03849
Низкий

7.5 High

CVSS2