Lucene search

K
cve[email protected]CVE-2010-3842
HistoryOct 28, 2010 - 12:00 a.m.

CVE-2010-3842

2010-10-2800:00:05
CWE-22
web.nvd.nist.gov
26
cve
path traversal
vulnerability
curl
remote-header-name
content-disposition
http header
nvd

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.1%

Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

Affected configurations

NVD
Node
curlcurlMatch7.20.0
OR
curlcurlMatch7.20.1
OR
curlcurlMatch7.21.1

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.1%