Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-10-27 17:00
Updated : 2010-10-27 21:00
NVD link : CVE-2010-3842
Mitre link : CVE-2010-3842
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
curl
- curl