PT-2010-4156 · Ea · Battlefield 2+1

Publicado

2010-07-02

·

Atualizado

2010-07-06

·

CVE-2010-2627

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Battlefield 2 versions 1.50 (1.5.3153-802.0) and earlier Battlefield 2142 versions 1.10.48.0 and earlier
Description The issue allows remote servers to overwrite arbitrary files on the client via ".." (dot dot backslash) sequences in URLs for the sponsor or community logos, and other URLs related to DemoDownloadURL, DemoIndexURL, and CustomMapsURL.
Recommendations For Battlefield 2 versions 1.50 (1.5.3153-802.0) and earlier, consider restricting access to the sponsor and community logos URLs to minimize the risk of exploitation. For Battlefield 2142 versions 1.10.48.0 and earlier, avoid using the DemoDownloadURL, DemoIndexURL, and CustomMapsURL until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2627

Produtos afetados

Battlefield 2
Battlefield 2142