PT-2010-3714 · Orbit · Orbit Downloader
Publicado
2010-05-27
·
Atualizado
2018-10-10
·
CVE-2010-2104
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Orbit Downloader versions 3.0.0.4 through 3.0.0.5
Description
A directory traversal issue allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the
name attribute of a file element.Recommendations
For Orbit Downloader versions 3.0.0.4 and 3.0.0.5, consider avoiding the use of metalink files until a patch is available, and restrict access to sensitive directories to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Orbit Downloader