PT-2010-4156 · Ea · Battlefield 2+1

Published

2010-07-02

·

Updated

2010-07-06

·

CVE-2010-2627

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Battlefield 2 versions 1.50 (1.5.3153-802.0) and earlier Battlefield 2142 versions 1.10.48.0 and earlier
Description The issue allows remote servers to overwrite arbitrary files on the client via ".." (dot dot backslash) sequences in URLs for the sponsor or community logos, and other URLs related to DemoDownloadURL, DemoIndexURL, and CustomMapsURL.
Recommendations For Battlefield 2 versions 1.50 (1.5.3153-802.0) and earlier, consider restricting access to the sponsor and community logos URLs to minimize the risk of exploitation. For Battlefield 2142 versions 1.10.48.0 and earlier, avoid using the DemoDownloadURL, DemoIndexURL, and CustomMapsURL until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2627

Affected Products

Battlefield 2
Battlefield 2142