Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24684
HistoryApr 10, 2020 - 1:01 a.m.

Directory Traversal

2020-04-1001:01:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.005

Percentile

76.3%

kdenetwork is vulnerable to directory traversal. The vulnerability exists as a flaw was found in the way KGet, a download manager, handled the “file” element in Metalink files. An attacker could use this flaw to create a specially-crafted Metalink file that, when opened, would cause KGet to overwrite arbitrary files accessible to the user running KGet.

References