PT-2010-2656 · Perforce · Perforce Server

Published

2010-03-05

·

Updated

2012-06-15

·

CVE-2010-0933

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Perforce Server version 2008.1
Description The issue allows remote authenticated users to create arbitrary files by utilizing a .. (dot dot) in the argument to the p4 add command, which is a directory traversal vulnerability.
Recommendations For Perforce Server version 2008.1, update to a version that fixes this issue to prevent remote authenticated users from creating arbitrary files.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0933

Affected Products

Perforce Server